14,642 vulnerabilities published in 2017
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption)
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption)
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey functio
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows att
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap u
Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attack
Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking wheth
RealPlayer 16.0.2.32 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) v
poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted
VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacke
Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local
In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks conta
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potent
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of
MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and dele
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer
In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based bu
In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based b
In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory co
In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-bas
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be rea
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they shoul
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows R
VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SV
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi
The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the p
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
A vulnerability in the ConfD server component of Cisco Elastic Services Controllers could allow an authenticated, local
A vulnerability in the Virtual Network Function Manager's (VNFM) logging function of Cisco Ultra Services Platform could
A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to vie
A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwg
In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.
In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.
In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwr
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started