2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16836 | MEDIUM | 6.1 | 2.0% | Nov 16, 2017 | Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via... |
| CVE-2017-5532 | MEDIUM | 5.4 | 0.7% | Nov 15, 2017 | A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edi... |
| CVE-2017-16833 | MEDIUM | 6.1 | 0.8% | Nov 15, 2017 | Stored cross-site scripting (XSS) vulnerability in Gemirro before 0.16.0 allows attackers to inject arbitrary web script... |
| CVE-2017-16821 | MEDIUM | 5.4 | 0.5% | Nov 15, 2017 | b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a craft... |
| CVE-2017-11877 | MEDIUM | 5.5 | 4.5% | Nov 15, 2017 | Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft... |
| CVE-2017-8806 | MEDIUM | 5.5 | 0.4% | Nov 13, 2017 | The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-commo... |
| CVE-2017-16792 | MEDIUM | 6.1 | 1.1% | Nov 13, 2017 | Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject ... |
| CVE-2017-16798 | MEDIUM | 5.4 | 0.9% | Nov 12, 2017 | In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file ex... |
| CVE-2017-16765 | MEDIUM | 6.1 | 1.0% | Nov 10, 2017 | XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi. |
| CVE-2017-16568 | MEDIUM | 5.4 | 2.0% | Nov 10, 2017 | Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality.... |
| CVE-2017-16567 | MEDIUM | 5.4 | 2.2% | Nov 10, 2017 | Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. T... |
| CVE-2017-14360 | MEDIUM | 5.9 | 2.3% | Nov 8, 2017 | A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability... |
| CVE-2017-2913 | MEDIUM | 5.9 | 0.7% | Nov 7, 2017 | An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific ... |
| CVE-2017-2912 | MEDIUM | 5.9 | 0.7% | Nov 7, 2017 | An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SS... |
| CVE-2017-2911 | MEDIUM | 5.9 | 0.7% | Nov 7, 2017 | An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SS... |
| CVE-2017-12096 | MEDIUM | 6.5 | 0.7% | Nov 7, 2017 | An exploitable vulnerability exists in the WiFi management of Circle with Disney. A crafted Access Point with the same n... |
| CVE-2017-12083 | MEDIUM | 5.8 | 1.1% | Nov 7, 2017 | An exploitable information disclosure vulnerability exists in the apid daemon of the Circle with Disney running firmware... |
| CVE-2017-14023 | MEDIUM | 4.9 | 3.7% | Nov 6, 2017 | An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13... |
| CVE-2017-16541 | MEDIUM | 6.5 | 3.7% | Nov 4, 2017 | Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discove... |
| CVE-2017-16539 | MEDIUM | 5.9 | 1.8% | Nov 4, 2017 | The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, ... |
| CVE-2017-16534 | MEDIUM | 6.8 | 0.4% | Nov 4, 2017 | The cdc_parse_cdc_header function in drivers/usb/core/message.c in the Linux kernel before 4.13.6 allows local users to ... |
| CVE-2017-16533 | MEDIUM | 6.6 | 0.4% | Nov 4, 2017 | The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause... |
| CVE-2017-16532 | MEDIUM | 6.6 | 0.4% | Nov 4, 2017 | The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause... |
| CVE-2017-16531 | MEDIUM | 6.6 | 0.4% | Nov 4, 2017 | drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-boun... |
| CVE-2017-16530 | MEDIUM | 6.6 | 0.4% | Nov 4, 2017 | The uas driver in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now