2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14859 | MEDIUM | 5.5 | 1.1% | Sep 29, 2017 | An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vul... |
| CVE-2017-12239 | MEDIUM | 6.8 | 0.4% | Sep 29, 2017 | A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Ci... |
| CVE-2017-12238 | MEDIUM | 6.5 | 2.0% | Sep 29, 2017 | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Se... |
| CVE-2017-12232 | MEDIUM | 6.5 | 2.2% | Sep 29, 2017 | A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers r... |
| CVE-2017-14737 | MEDIUM | 5.5 | 0.3% | Sep 26, 2017 | A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.... |
| CVE-2017-14506 | MEDIUM | 5.4 | 0.7% | Sep 25, 2017 | geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homep... |
| CVE-2017-14651 | MEDIUM | 4.8 | 3.8% | Sep 21, 2017 | WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or ... |
| CVE-2017-14633 | MEDIUM | 6.5 | 1.9% | Sep 21, 2017 | In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapp... |
| CVE-2017-6720 | MEDIUM | 6.5 | 1.4% | Sep 21, 2017 | A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an aut... |
| CVE-2017-14604 | MEDIUM | 6.5 | 2.5% | Sep 20, 2017 | GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrate... |
| CVE-2017-12168 | MEDIUM | 6 | 0.4% | Sep 20, 2017 | The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM gues... |
| CVE-2017-14528 | MEDIUM | 6.5 | 2.6% | Sep 18, 2017 | The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFF... |
| CVE-2017-4925 | MEDIUM | 5.5 | 0.4% | Sep 15, 2017 | VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ... |
| CVE-2017-14420 | MEDIUM | 5.9 | 0.5% | Sep 13, 2017 | The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (... |
| CVE-2017-14419 | MEDIUM | 5.9 | 0.8% | Sep 13, 2017 | The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (... |
| CVE-2017-14416 | MEDIUM | 6.1 | 1.1% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/... |
| CVE-2017-14415 | MEDIUM | 6.1 | 1.1% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/... |
| CVE-2017-14414 | MEDIUM | 6.1 | 1.1% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/... |
| CVE-2017-14413 | MEDIUM | 6.1 | 1.1% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/... |
| CVE-2017-8758 | MEDIUM | 6.1 | 3.4% | Sep 13, 2017 | Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access... |
| CVE-2017-14341 | MEDIUM | 6.5 | 2.0% | Sep 12, 2017 | ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted... |
| CVE-2017-8041 | MEDIUM | 6.1 | 0.9% | Sep 9, 2017 | In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a use... |
| CVE-2017-8040 | MEDIUM | 6.5 | 1.1% | Sep 9, 2017 | In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XX... |
| CVE-2017-9095 | MEDIUM | 5.5 | 3.7% | Sep 8, 2017 | XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled d... |
| CVE-2017-14175 | MEDIUM | 6.5 | 2.1% | Sep 7, 2017 | In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of File) check might caus... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now