2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17082 | — | — | — | Dec 3, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-14516 | — | — | 0.6% | Dec 3, 2017 | Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security No... |
| CVE-2017-17095 | — | — | 10.6% | Dec 2, 2017 | tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-b... |
| CVE-2017-17094 | — | — | 2.4% | Dec 2, 2017 | wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might... |
| CVE-2017-17093 | — | — | 2.4% | Dec 2, 2017 | wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML elem... |
| CVE-2017-17092 | — | — | 4.1% | Dec 2, 2017 | wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js fi... |
| CVE-2017-17091 | — | — | 8.2% | Dec 2, 2017 | wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from t... |
| CVE-2017-17090 | — | — | 81.5% | Dec 2, 2017 | An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and old... |
| CVE-2017-6679 | MEDIUM | 6.4 | 0.4% | Dec 1, 2017 | The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (... |
| CVE-2017-16953 | — | — | 11.3% | Dec 1, 2017 | connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo... |
| CVE-2017-16895 | HIGH | 7.8 | 1.0% | Dec 1, 2017 | The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper... |
| CVE-2017-16893 | — | — | 1.4% | Dec 1, 2017 | The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerabi... |
| CVE-2017-16612 | — | — | 5.2% | Dec 1, 2017 | libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing maliciou... |
| CVE-2017-16611 | MEDIUM | 5.5 | 0.4% | Dec 1, 2017 | In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as roo... |
| CVE-2017-15357 | — | — | 1.2% | Dec 1, 2017 | The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges v... |
| CVE-2017-14953 | — | — | 0.5% | Dec 1, 2017 | HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger associat... |
| CVE-2017-14487 | — | — | 1.2% | Dec 1, 2017 | The OhMiBod Remote app for Android and iOS allows remote attackers to impersonate users by sniffing network traffic for ... |
| CVE-2017-14486 | — | — | 0.8% | Dec 1, 2017 | The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages... |
| CVE-2017-13664 | — | — | 1.5% | Dec 1, 2017 | Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitr... |
| CVE-2017-13663 | — | — | 0.4% | Dec 1, 2017 | Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log f... |
| CVE-2017-15707 | — | — | 4.9% | Dec 1, 2017 | In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perf... |
| CVE-2017-15702 | CRITICAL | 9.8 | 6.2% | Dec 1, 2017 | In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on differ... |
| CVE-2017-15701 | HIGH | 7.5 | 4.4% | Dec 1, 2017 | In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame si... |
| CVE-2017-10903 | — | — | 2.6% | Dec 1, 2017 | Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device wit... |
| CVE-2017-10902 | — | — | 2.3% | Dec 1, 2017 | PTW-WMS1 firmware version 2.000.012 allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now