2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1596 | — | — | 0.3% | Dec 20, 2017 | IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information... |
| CVE-2017-1595 | — | — | 0.3% | Dec 20, 2017 | IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information... |
| CVE-2017-15532 | — | — | 1.4% | Dec 20, 2017 | Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory trave... |
| CVE-2017-14969 | — | — | 0.4% | Dec 20, 2017 | In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not val... |
| CVE-2017-14968 | — | — | 0.4% | Dec 20, 2017 | In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not val... |
| CVE-2017-14967 | — | — | 0.4% | Dec 20, 2017 | In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not val... |
| CVE-2017-14966 | — | — | 0.4% | Dec 20, 2017 | In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not val... |
| CVE-2017-14965 | — | — | 0.4% | Dec 20, 2017 | In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not val... |
| CVE-2017-14964 | — | — | 0.4% | Dec 20, 2017 | In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not val... |
| CVE-2017-14963 | — | — | 0.4% | Dec 20, 2017 | In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not val... |
| CVE-2017-14962 | — | — | 0.4% | Dec 20, 2017 | In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Out of Bounds Write vulnerability because of not... |
| CVE-2017-1494 | — | — | 0.8% | Dec 20, 2017 | IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2017-1423 | — | — | 1.3% | Dec 20, 2017 | IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge... |
| CVE-2017-1270 | — | — | 0.3% | Dec 20, 2017 | IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to sessi... |
| CVE-2017-1266 | — | — | 0.5% | Dec 20, 2017 | IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to ... |
| CVE-2017-1262 | — | — | 1.2% | Dec 20, 2017 | IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulner... |
| CVE-2017-1261 | — | — | 0.3% | Dec 20, 2017 | IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM... |
| CVE-2017-1257 | — | — | 1.1% | Dec 20, 2017 | IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount f... |
| CVE-2017-12072 | — | — | 1.0% | Dec 20, 2017 | Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows re... |
| CVE-2017-17476 | — | — | 2.2% | Dec 20, 2017 | Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support ... |
| CVE-2017-16818 | — | — | 2.3% | Dec 20, 2017 | RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion fa... |
| CVE-2017-17752 | — | — | 1.4% | Dec 20, 2017 | Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code execute... |
| CVE-2017-4943 | — | — | 0.4% | Dec 20, 2017 | VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the ... |
| CVE-2017-4941 | HIGH | 8.8 | 3.2% | Dec 20, 2017 | VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8... |
| CVE-2017-4940 | MEDIUM | 6.1 | 0.9% | Dec 20, 2017 | The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESX... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now