2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8038 | — | — | 0.9% | Nov 27, 2017 | In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated ... |
| CVE-2017-8031 | MEDIUM | 5.3 | 1.1% | Nov 27, 2017 | An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior... |
| CVE-2017-8028 | — | — | 2.6% | Nov 27, 2017 | In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bo... |
| CVE-2017-4995 | HIGH | 8.1 | 2.5% | Nov 27, 2017 | An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. Wh... |
| CVE-2017-16962 | — | — | 2.2% | Nov 27, 2017 | The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi... |
| CVE-2017-16961 | — | — | 1.4% | Nov 27, 2017 | A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated att... |
| CVE-2017-16960 | — | — | 2.4% | Nov 27, 2017 | TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell... |
| CVE-2017-16959 | — | — | 1.9% | Nov 27, 2017 | The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users ... |
| CVE-2017-16958 | — | — | 2.9% | Nov 27, 2017 | TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell... |
| CVE-2017-16957 | — | — | 5.6% | Nov 27, 2017 | TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell... |
| CVE-2017-16956 | — | — | 0.7% | Nov 27, 2017 | b3log Symphony (aka Sym) 2.2.0 allows an XSS attack by sending a private letter with a certain /article URI, and a secon... |
| CVE-2017-16955 | — | — | 2.0% | Nov 27, 2017 | SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitr... |
| CVE-2017-14390 | — | — | 1.4% | Nov 27, 2017 | In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to b... |
| CVE-2017-14176 | — | — | 6.0% | Nov 27, 2017 | Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh U... |
| CVE-2017-16948 | — | — | 0.3% | Nov 26, 2017 | TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possib... |
| CVE-2017-16946 | — | — | 1.1% | Nov 25, 2017 | The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which... |
| CVE-2017-16944 | — | — | 63.3% | Nov 25, 2017 | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial... |
| CVE-2017-16943 | — | — | 46.7% | Nov 25, 2017 | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitr... |
| CVE-2017-16942 | — | — | 1.2% | Nov 25, 2017 | In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the function wav_w64_read_fmt_chunk() in wav_w6... |
| CVE-2017-16941 | — | — | 1.6% | Nov 25, 2017 | October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to exec... |
| CVE-2017-16939 | HIGH | 7.8 | 2.1% | Nov 24, 2017 | The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gai... |
| CVE-2017-16938 | — | — | 1.8% | Nov 24, 2017 | A global buffer overflow in OptiPNG 0.7.6 allows remote attackers to cause a denial-of-service attack or other unspecifi... |
| CVE-2017-16936 | — | — | 1.0% | Nov 24, 2017 | Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9... |
| CVE-2017-16935 | — | — | 7.7% | Nov 24, 2017 | Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to... |
| CVE-2017-16934 | — | — | 13.5% | Nov 24, 2017 | The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin pas... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now