2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-8038In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated ...
CVE-2017-8031MEDIUM5.3An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior...
CVE-2017-8028In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bo...
CVE-2017-4995HIGH8.1An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. Wh...
CVE-2017-16962The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi...
CVE-2017-16961A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated att...
CVE-2017-16960TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell...
CVE-2017-16959The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users ...
CVE-2017-16958TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell...
CVE-2017-16957TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell...
CVE-2017-16956b3log Symphony (aka Sym) 2.2.0 allows an XSS attack by sending a private letter with a certain /article URI, and a secon...
CVE-2017-16955SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitr...
CVE-2017-14390In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to b...
CVE-2017-14176Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh U...
CVE-2017-16948TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possib...
CVE-2017-16946The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which...
CVE-2017-16944The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial...
CVE-2017-16943The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitr...
CVE-2017-16942In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the function wav_w64_read_fmt_chunk() in wav_w6...
CVE-2017-16941October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to exec...
CVE-2017-16939HIGH7.8The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gai...
CVE-2017-16938A global buffer overflow in OptiPNG 0.7.6 allows remote attackers to cause a denial-of-service attack or other unspecifi...
CVE-2017-16936Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9...
CVE-2017-16935Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to...
CVE-2017-16934The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin pas...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now