Vulnerabilities (CVE)

Total 398846 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-10917 1 Xen 1 Xen 2026-06-17 9.4 HIGH 9.1 CRITICAL
Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.
CVE-2017-10916 1 Xen 1 Xen 2026-06-17 5.0 MEDIUM 7.5 HIGH
The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.
CVE-2017-10915 1 Xen 1 Xen 2026-06-17 6.8 MEDIUM 9.0 CRITICAL
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
CVE-2017-10914 1 Xen 1 Xen 2026-06-17 6.8 MEDIUM 8.1 HIGH
The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.
CVE-2017-10913 1 Xen 1 Xen 2026-06-17 7.5 HIGH 9.8 CRITICAL
The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1.
CVE-2017-10912 1 Xen 1 Xen 2026-06-17 10.0 HIGH 10.0 CRITICAL
Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.
CVE-2017-10911 1 Linux 1 Linux Kernel 2026-06-17 4.9 MEDIUM 6.5 MEDIUM
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
CVE-2017-10910 1 Mqtt.js Project 1 Mqtt.js 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service condition.
CVE-2017-10909 1 Sony 1 Music Center 2026-06-17 9.3 HIGH 7.8 HIGH
Untrusted search path vulnerability in Music Center for PC version 1.0.01 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
CVE-2017-10908 1 Dena 1 H2o 2026-06-17 5.0 MEDIUM 7.5 HIGH
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.
CVE-2017-10907 1 Spiqe 1 Onethird Cms Show Off 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
Directory traversal vulnerability in OneThird CMS Show Off v1.85 and earlier. Show Off v1.85 en and earlier allows an attacker to read arbitrary files via unspecified vectors.
CVE-2017-10906 2 Fluentd, Redhat 2 Fluentd, Openstack 2026-06-17 10.0 HIGH 9.8 CRITICAL
Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.
CVE-2017-10905 1 Qt 1 Qt 2026-06-17 6.8 MEDIUM 5.3 MEDIUM
A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.
CVE-2017-10904 1 Qt 1 Qt 2026-06-17 7.5 HIGH 9.8 CRITICAL
Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
CVE-2017-10903 1 Princeton 2 Ptw-wms1, Ptw-wms1 Firmware 2026-06-17 10.0 HIGH 9.8 CRITICAL
Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device with root privileges and conduct arbitrary operations via unspecified vectors.
CVE-2017-10902 1 Princeton 2 Ptw-wms1, Ptw-wms1 Firmware 2026-06-17 10.0 HIGH 9.8 CRITICAL
PTW-WMS1 firmware version 2.000.012 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
CVE-2017-10901 1 Princeton 2 Ptw-wms1, Ptw-wms1 Firmware 2026-06-17 5.0 MEDIUM 7.5 HIGH
Buffer overflow in PTW-WMS1 firmware version 2.000.012 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.
CVE-2017-10900 1 Princeton 2 Ptw-wms1, Ptw-wms1 Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
PTW-WMS1 firmware version 2.000.012 allows remote attackers to bypass access restrictions to obtain or delete data on the disk via unspecified vectors.
CVE-2017-10899 1 Ark-web 1 A-reserve 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-10898 1 Ark-web 1 A-member 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.