2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-2285MEDIUM6.1Cross-site scripting vulnerability in Simple Custom CSS and JS prior to version 3.4 allows remote attackers to inject ar...
CVE-2017-12061MEDIUM6.1An XSS issue was discovered in admin/install.php in MantisBT before 1.3.12 and 2.x before 2.5.2. Some variables under us...
CVE-2017-1303MEDIUM6.1IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerab...
CVE-2017-11548MEDIUM5.5The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of servic...
CVE-2017-11331MEDIUM5.5The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of serv...
CVE-2017-9491MEDIUM5.3The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firm...
CVE-2017-9476MEDIUM6.5The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firm...
CVE-2017-11683MEDIUM6.5There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 tha...
CVE-2017-11682MEDIUM6.1Stored Cross-site scripting vulnerability in Hashtopussy 0.4.0 allows remote attackers to inject arbitrary web script or...
CVE-2017-11654MEDIUM5.9An out-of-bounds read and write flaw was found in the way SIPcrack 0.2 processed SIP traffic, because 0x00 termination o...
CVE-2017-11651MEDIUM6.1NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag.
CVE-2017-8919MEDIUM6.5NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API...
CVE-2017-11458MEDIUM6.1Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote ...
CVE-2017-11457MEDIUM6.5XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated us...
CVE-2017-11434MEDIUM5.5The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of ...
CVE-2017-11448MEDIUM6.5The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive in...
CVE-2017-11447MEDIUM6.5The ReadSCREENSHOTImage function in coders/screenshot.c in ImageMagick before 7.0.6-1 has memory leaks, causing denial o...
CVE-2017-9340MEDIUM6.5An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before ...
CVE-2017-9339MEDIUM5.3A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus gran...
CVE-2017-9338MEDIUM5.4Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10...
CVE-2017-3100MEDIUM6.5Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Scr...
CVE-2017-3080MEDIUM6.5Adobe Flash Player versions 26.0.0.131 and earlier have a security bypass vulnerability related to the Flash API used by...
CVE-2017-2347MEDIUM6.5A denial of service vulnerability in rpd daemon of Juniper Networks Junos OS allows a malformed MPLS ping packet to cras...
CVE-2017-2346MEDIUM5.9An MS-MPC or MS-MIC Service PIC may crash when large fragmented packets are passed through an Application Layer Gateway ...
CVE-2017-11352MEDIUM6.5In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle....

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now