14,642 vulnerabilities published in 2017
An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user
Symantec Endpoint Protection prior to SEP 12.1 RU6 MP9 could be susceptible to a privilege escalation vulnerability, whi
The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access t
Special crafted InPage document leads to arbitrary code execution in InPage reader.
backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a
The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote at
In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows re
In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an alloclen_64 multiplication of width
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS b
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "APFS" compo
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Audio" comp
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Remote Mana
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "AppleScript
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "fsck_msdos"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ImageIO" co
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Open Script
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CoreText" c
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFNetwork"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "HFS" compon
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFNetwork"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Sandbox" co
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Quick Look"
An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3
Untrusted search path vulnerability in HYPER SBI Ver. 2.2 and earlier allows an attacker to gain privileges via a Trojan
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access
A local privilege escalation vulnerability was identified in the Realtek audio driver versions prior to 6.0.1.8224 in so
Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially craf
In AutomationDirect CLICK Programming Software (Part Number C0-PGMSW) Versions 2.10 and prior; C-More Programming Softwa
An elevation of privilege vulnerability exists in the NVIDIA GPU driver (gm20b_clk_throt_set_cdev_state), where an out o
Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT1, Windows Server 2012 and R2, Wi
Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by f
The coff_slurp_line_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distribute
The aout_get_external_symbols function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distribut
The display_debug_frames function in dwarf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service
The _bfd_elf_parse_gnu_properties function in elf-properties.c in the Binary File Descriptor (BFD) library (aka libbfd),
The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32
coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not vali
The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed i
In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating
The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended ne
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started