2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-2285 | MEDIUM | 6.1 | 1.5% | Aug 2, 2017 | Cross-site scripting vulnerability in Simple Custom CSS and JS prior to version 3.4 allows remote attackers to inject ar... |
| CVE-2017-12061 | MEDIUM | 6.1 | 2.9% | Aug 1, 2017 | An XSS issue was discovered in admin/install.php in MantisBT before 1.3.12 and 2.x before 2.5.2. Some variables under us... |
| CVE-2017-1303 | MEDIUM | 6.1 | 1.3% | Jul 31, 2017 | IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerab... |
| CVE-2017-11548 | MEDIUM | 5.5 | 3.9% | Jul 31, 2017 | The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of servic... |
| CVE-2017-11331 | MEDIUM | 5.5 | 3.8% | Jul 31, 2017 | The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of serv... |
| CVE-2017-9491 | MEDIUM | 5.3 | 1.3% | Jul 31, 2017 | The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firm... |
| CVE-2017-9476 | MEDIUM | 6.5 | 1.7% | Jul 31, 2017 | The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firm... |
| CVE-2017-11683 | MEDIUM | 6.5 | 2.7% | Jul 27, 2017 | There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 tha... |
| CVE-2017-11682 | MEDIUM | 6.1 | 0.8% | Jul 27, 2017 | Stored Cross-site scripting vulnerability in Hashtopussy 0.4.0 allows remote attackers to inject arbitrary web script or... |
| CVE-2017-11654 | MEDIUM | 5.9 | 2.0% | Jul 26, 2017 | An out-of-bounds read and write flaw was found in the way SIPcrack 0.2 processed SIP traffic, because 0x00 termination o... |
| CVE-2017-11651 | MEDIUM | 6.1 | 0.7% | Jul 26, 2017 | NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag. |
| CVE-2017-8919 | MEDIUM | 6.5 | 1.3% | Jul 25, 2017 | NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API... |
| CVE-2017-11458 | MEDIUM | 6.1 | 1.0% | Jul 25, 2017 | Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote ... |
| CVE-2017-11457 | MEDIUM | 6.5 | 1.4% | Jul 25, 2017 | XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated us... |
| CVE-2017-11434 | MEDIUM | 5.5 | 0.4% | Jul 25, 2017 | The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of ... |
| CVE-2017-11448 | MEDIUM | 6.5 | 2.7% | Jul 19, 2017 | The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive in... |
| CVE-2017-11447 | MEDIUM | 6.5 | 2.2% | Jul 19, 2017 | The ReadSCREENSHOTImage function in coders/screenshot.c in ImageMagick before 7.0.6-1 has memory leaks, causing denial o... |
| CVE-2017-9340 | MEDIUM | 6.5 | 1.0% | Jul 17, 2017 | An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before ... |
| CVE-2017-9339 | MEDIUM | 5.3 | 1.0% | Jul 17, 2017 | A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus gran... |
| CVE-2017-9338 | MEDIUM | 5.4 | 0.6% | Jul 17, 2017 | Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10... |
| CVE-2017-3100 | MEDIUM | 6.5 | 3.7% | Jul 17, 2017 | Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Scr... |
| CVE-2017-3080 | MEDIUM | 6.5 | 4.2% | Jul 17, 2017 | Adobe Flash Player versions 26.0.0.131 and earlier have a security bypass vulnerability related to the Flash API used by... |
| CVE-2017-2347 | MEDIUM | 6.5 | 1.9% | Jul 17, 2017 | A denial of service vulnerability in rpd daemon of Juniper Networks Junos OS allows a malformed MPLS ping packet to cras... |
| CVE-2017-2346 | MEDIUM | 5.9 | 1.1% | Jul 17, 2017 | An MS-MPC or MS-MIC Service PIC may crash when large fragmented packets are passed through an Application Layer Gateway ... |
| CVE-2017-11352 | MEDIUM | 6.5 | 1.8% | Jul 17, 2017 | In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now