2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17428 | — | — | 15.0% | Mar 5, 2018 | Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS cip... |
| CVE-2017-16922 | — | — | 1.4% | Mar 5, 2018 | In com.wowza.wms.timedtext.http.HTTPProviderCaptionFile in Wowza Streaming Engine before 4.7.1, traversal of the directo... |
| CVE-2017-7633 | — | — | 1.3% | Mar 5, 2018 | QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this ma... |
| CVE-2017-7437 | MEDIUM | 4.6 | 0.8% | Mar 5, 2018 | NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "acco... |
| CVE-2017-7427 | MEDIUM | 5.4 | 0.8% | Mar 5, 2018 | Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Ide... |
| CVE-2017-18214 | HIGH | 7.5 | 3.7% | Mar 4, 2018 | The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string... |
| CVE-2017-18213 | — | — | 1.4% | Mar 4, 2018 | In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges. |
| CVE-2017-9285 | MEDIUM | 5.4 | 1.2% | Mar 2, 2018 | NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted acces... |
| CVE-2017-9280 | MEDIUM | 4.3 | 1.1% | Mar 2, 2018 | Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potenti... |
| CVE-2017-9279 | LOW | 2 | 0.9% | Mar 2, 2018 | NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes ... |
| CVE-2017-9278 | LOW | 3.3 | 0.9% | Mar 2, 2018 | The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password,... |
| CVE-2017-9277 | MEDIUM | 4.2 | 1.4% | Mar 2, 2018 | The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open... |
| CVE-2017-9276 | MEDIUM | 5.4 | 0.8% | Mar 2, 2018 | Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be re... |
| CVE-2017-9267 | MEDIUM | 6.5 | 1.0% | Mar 2, 2018 | In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ci... |
| CVE-2017-7438 | MEDIUM | 4.6 | 0.6% | Mar 2, 2018 | NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modif... |
| CVE-2017-7434 | LOW | 3.3 | 0.9% | Mar 2, 2018 | In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwor... |
| CVE-2017-7429 | HIGH | 8.8 | 0.9% | Mar 2, 2018 | The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code ... |
| CVE-2017-7419 | MEDIUM | 4.6 | 0.8% | Mar 2, 2018 | A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks d... |
| CVE-2017-5189 | MEDIUM | 4.3 | 1.2% | Mar 2, 2018 | NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel,... |
| CVE-2017-14802 | MEDIUM | 5.4 | 1.0% | Mar 2, 2018 | Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to tr... |
| CVE-2017-14801 | MEDIUM | 4.6 | 0.8% | Mar 2, 2018 | Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using ... |
| CVE-2017-1787 | MEDIUM | 4.4 | 0.4% | Mar 2, 2018 | IBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administr... |
| CVE-2017-1654 | MEDIUM | 4 | 0.4% | Mar 2, 2018 | IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump f... |
| CVE-2017-15130 | — | — | 2.6% | Mar 2, 2018 | A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could ... |
| CVE-2017-14461 | MEDIUM | 5.9 | 17.6% | Mar 2, 2018 | A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resultin... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now