2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12329A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow a...
CVE-2017-12328A vulnerability in Session Initiation Protocol (SIP) call handling in Cisco IP Phone 8800 Series devices could allow an ...
CVE-2017-12297A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to a...
CVE-2017-17067Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and ...
CVE-2017-14198An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to...
CVE-2017-14197An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site...
CVE-2017-14196An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a P...
CVE-2017-14591Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through f...
CVE-2017-14189An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI...
CVE-2017-14186A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions un...
CVE-2017-8818curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access an...
CVE-2017-8817CRITICAL9.8The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of...
CVE-2017-8816CRITICAL9.8The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial...
CVE-2017-14378EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow attackers to bypass authenti...
CVE-2017-14377EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Ser...
CVE-2017-17059XSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts or wp-thumb-post) plugin 8.1.3 for WordPress via...
CVE-2017-13872An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is...
CVE-2017-17058HIGH7.5The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco...
CVE-2017-17054In aubio 0.4.6, a divide-by-zero error exists in the function new_aubio_source_wavread() in source_wavread.c, which may ...
CVE-2017-17053HIGH7The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux kernel before 4.12.10 does not correctl...
CVE-2017-17052HIGH7.8The mm_init function in kernel/fork.c in the Linux kernel before 4.12.10 does not clear the ->exe_file member of a new p...
CVE-2017-17050TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possib...
CVE-2017-17049TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possib...
CVE-2017-17046An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information...
CVE-2017-17045An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensi...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now