2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-17428Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS cip...
CVE-2017-16922In com.wowza.wms.timedtext.http.HTTPProviderCaptionFile in Wowza Streaming Engine before 4.7.1, traversal of the directo...
CVE-2017-7633QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this ma...
CVE-2017-7437MEDIUM4.6NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "acco...
CVE-2017-7427MEDIUM5.4Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Ide...
CVE-2017-18214HIGH7.5The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string...
CVE-2017-18213In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges.
CVE-2017-9285MEDIUM5.4NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted acces...
CVE-2017-9280MEDIUM4.3Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potenti...
CVE-2017-9279LOW2NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes ...
CVE-2017-9278LOW3.3The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password,...
CVE-2017-9277MEDIUM4.2The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open...
CVE-2017-9276MEDIUM5.4Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be re...
CVE-2017-9267MEDIUM6.5In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ci...
CVE-2017-7438MEDIUM4.6NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modif...
CVE-2017-7434LOW3.3In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwor...
CVE-2017-7429HIGH8.8The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code ...
CVE-2017-7419MEDIUM4.6A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks d...
CVE-2017-5189MEDIUM4.3NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel,...
CVE-2017-14802MEDIUM5.4Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to tr...
CVE-2017-14801MEDIUM4.6Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using ...
CVE-2017-1787MEDIUM4.4IBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administr...
CVE-2017-1654MEDIUM4IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump f...
CVE-2017-15130A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could ...
CVE-2017-14461MEDIUM5.9A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resultin...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now