14,642 vulnerabilities published in 2017
The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to c
drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option
drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK o
Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux k
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows l
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which mak
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes
A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially crafted file to cause
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause me
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause me
A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbit
A remote code execution vulnerability in libstagefright could enable an attacker using a specially crafted file to execu
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary c
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute a
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute a
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execu
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit thi
A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows c
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A
A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially cra
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5.
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl ca
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, an
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, an
An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recoverable Format, an authe
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system
An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using
Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script fil
The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel
The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain pr
The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain pri
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of gu
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to ob
The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact vi
The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact
Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the
Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote att
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implem
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started