2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-17082Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2017-14516Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security No...
CVE-2017-17095tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-b...
CVE-2017-17094wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might...
CVE-2017-17093wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML elem...
CVE-2017-17092wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js fi...
CVE-2017-17091wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from t...
CVE-2017-17090An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and old...
CVE-2017-6679MEDIUM6.4The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (...
CVE-2017-16953connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo...
CVE-2017-16895HIGH7.8The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper...
CVE-2017-16893The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerabi...
CVE-2017-16612libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing maliciou...
CVE-2017-16611MEDIUM5.5In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as roo...
CVE-2017-15357The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges v...
CVE-2017-14953HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger associat...
CVE-2017-14487The OhMiBod Remote app for Android and iOS allows remote attackers to impersonate users by sniffing network traffic for ...
CVE-2017-14486The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages...
CVE-2017-13664Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitr...
CVE-2017-13663Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log f...
CVE-2017-15707In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perf...
CVE-2017-15702CRITICAL9.8In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on differ...
CVE-2017-15701HIGH7.5In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame si...
CVE-2017-10903Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device wit...
CVE-2017-10902PTW-WMS1 firmware version 2.000.012 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now