2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-10622 | CRITICAL | 9.8 | 5.4% | Oct 13, 2017 | An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote un... |
| CVE-2017-10615 | CRITICAL | 9.8 | 2.5% | Oct 13, 2017 | A vulnerability in the pluggable authentication module (PAM) of Juniper Networks Junos OS may allow an unauthenticated n... |
| CVE-2017-15041 | CRITICAL | 9.8 | 8.9% | Oct 5, 2017 | Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to... |
| CVE-2017-12149 | CRITICAL | 9.8 | 90.7% | Oct 4, 2017 | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter ... |
| CVE-2017-14491 | CRITICAL | 9.8 | 84.9% | Oct 4, 2017 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut... |
| CVE-2017-12166 | CRITICAL | 9.8 | 3.6% | Oct 4, 2017 | OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1... |
| CVE-2017-8021 | CRITICAL | 9.8 | 2.1% | Oct 3, 2017 | EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially b... |
| CVE-2017-14702 | CRITICAL | 9.8 | 8.3% | Sep 30, 2017 | ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.Upd... |
| CVE-2017-12240 | CRITICAL | 9.8 | 13.5% | Sep 29, 2017 | The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could al... |
| CVE-2017-12621 | CRITICAL | 9.8 | 8.5% | Sep 28, 2017 | During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a... |
| CVE-2017-10932 | CRITICAL | 9.8 | 4.1% | Sep 28, 2017 | All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, N... |
| CVE-2017-12905 | CRITICAL | 10 | 2.6% | Sep 25, 2017 | Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose in... |
| CVE-2017-14648 | CRITICAL | 9.8 | 3.4% | Sep 21, 2017 | A global buffer overflow was discovered in the iteration_loop function in loop.c in BladeEnc version 0.94.2. The vulnera... |
| CVE-2017-14632 | CRITICAL | 9.8 | 5.7% | Sep 21, 2017 | Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_... |
| CVE-2017-10930 | CRITICAL | 9.8 | 1.1% | Sep 19, 2017 | The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in or... |
| CVE-2017-14244 | CRITICAL | 9.8 | 17.1% | Sep 17, 2017 | An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows ... |
| CVE-2017-1002016 | CRITICAL | 9.8 | 2.6% | Sep 14, 2017 | Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to s... |
| CVE-2017-1002008 | CRITICAL | 9.8 | 16.9% | Sep 14, 2017 | Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membe... |
| CVE-2017-13725 | CRITICAL | 9.8 | 3.3% | Sep 14, 2017 | The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print(). |
| CVE-2017-13689 | CRITICAL | 9.8 | 3.2% | Sep 14, 2017 | The IKEv1 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:ikev1_id_print(). |
| CVE-2017-13688 | CRITICAL | 9.8 | 3.2% | Sep 14, 2017 | The OLSR parser in tcpdump before 4.9.2 has a buffer over-read in print-olsr.c:olsr_print(). |
| CVE-2017-13687 | CRITICAL | 9.8 | 3.3% | Sep 14, 2017 | The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print(). |
| CVE-2017-13055 | CRITICAL | 9.8 | 3.2% | Sep 14, 2017 | The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print_is_reach_subtlv(). |
| CVE-2017-13054 | CRITICAL | 9.8 | 3.2% | Sep 14, 2017 | The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_private_8023_print(). |
| CVE-2017-13053 | CRITICAL | 9.8 | 3.2% | Sep 14, 2017 | The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decode_rt_routing_info(). |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now