14,642 vulnerabilities published in 2017
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers
Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privile
The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based B
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be exec
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a lo
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privil
The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK optio
The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to c
drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option
drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK o
Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux k
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows l
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which mak
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes
A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially crafted file to cause
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause me
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause me
A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbit
A remote code execution vulnerability in libstagefright could enable an attacker using a specially crafted file to execu
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary c
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute a
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute a
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execu
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit thi
A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows c
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A
A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially cra
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5.
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl ca
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, an
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, an
An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recoverable Format, an authe
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system
An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using
Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script fil
The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel
The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain pr
The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain pri
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of gu
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started