2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17044 | — | — | 0.4% | Nov 28, 2017 | An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to cause a denial of service (infinite loop and... |
| CVE-2017-17043 | — | — | 5.1% | Nov 28, 2017 | The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/... |
| CVE-2017-17042 | — | — | 2.9% | Nov 28, 2017 | lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence... |
| CVE-2017-9315 | — | — | 1.4% | Nov 28, 2017 | Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary passw... |
| CVE-2017-16952 | — | — | 3.2% | Nov 28, 2017 | KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file. |
| CVE-2017-16951 | MEDIUM | 5.5 | 3.2% | Nov 28, 2017 | Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, o... |
| CVE-2017-15673 | — | — | 1.9% | Nov 28, 2017 | The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP ... |
| CVE-2017-8020 | — | — | 4.2% | Nov 28, 2017 | An issue was discovered in EMC ScaleIO 2.0.1.x. A buffer overflow vulnerability in the SDBG service may potentially allo... |
| CVE-2017-8019 | — | — | 2.0% | Nov 28, 2017 | An issue was discovered in EMC ScaleIO 2.0.1.x. A vulnerability in message parsers (MDM, SDS, and LIA) could potentially... |
| CVE-2017-8001 | HIGH | 8.4 | 0.4% | Nov 28, 2017 | An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials... |
| CVE-2017-14389 | MEDIUM | 6.5 | 0.9% | Nov 28, 2017 | An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all version... |
| CVE-2017-14379 | — | — | 0.9% | Nov 28, 2017 | EMC RSA Authentication Manager before 8.2 SP1 P6 has a cross-site scripting vulnerability that could potentially be expl... |
| CVE-2017-15275 | HIGH | 7.5 | 21.4% | Nov 27, 2017 | Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to c... |
| CVE-2017-14746 | CRITICAL | 9.8 | 9.9% | Nov 27, 2017 | Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted S... |
| CVE-2017-1689 | — | — | 0.7% | Nov 27, 2017 | IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2017-1688 | — | — | 0.7% | Nov 27, 2017 | IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2017-1678 | — | — | 0.7% | Nov 27, 2017 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2017-1650 | — | — | 0.7% | Nov 27, 2017 | IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2017-1628 | — | — | 1.8% | Nov 27, 2017 | IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST A... |
| CVE-2017-1607 | — | — | 0.7% | Nov 27, 2017 | IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2017-1593 | — | — | 0.7% | Nov 27, 2017 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2017-1570 | — | — | 0.9% | Nov 27, 2017 | IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from stack traces. IBM X-... |
| CVE-2017-1560 | — | — | 0.7% | Nov 27, 2017 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2017-1484 | — | — | 1.0% | Nov 27, 2017 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an authenticated attacke... |
| CVE-2017-1461 | — | — | 0.7% | Nov 27, 2017 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows u... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now