2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5710 | — | — | 0.6% | Nov 21, 2017 | Multiple privilege escalations in kernel in Intel Trusted Execution Engine Firmware 3.0 allows unauthorized process to a... |
| CVE-2017-5709 | — | — | 0.6% | Nov 21, 2017 | Multiple privilege escalations in kernel in Intel Server Platform Services Firmware 4.0 allows unauthorized process to a... |
| CVE-2017-5708 | — | — | 0.6% | Nov 21, 2017 | Multiple privilege escalations in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow un... |
| CVE-2017-5707 | — | — | 0.6% | Nov 21, 2017 | Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to t... |
| CVE-2017-5706 | — | — | 0.7% | Nov 21, 2017 | Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4.0 allow attacker with local access to t... |
| CVE-2017-5705 | — | — | 0.7% | Nov 21, 2017 | Multiple buffer overflows in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow attacke... |
| CVE-2017-16923 | — | — | 2.5% | Nov 21, 2017 | Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_k... |
| CVE-2017-16664 | — | — | 2.5% | Nov 21, 2017 | Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26... |
| CVE-2017-16920 | — | — | 2.1% | Nov 21, 2017 | v5/config/system.php in dayrui FineCms 5.2.0 has a default SYS_KEY value and does not require key regeneration for each ... |
| CVE-2017-16613 | — | — | 8.4% | Nov 21, 2017 | An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1... |
| CVE-2017-15044 | — | — | 2.1% | Nov 21, 2017 | The default installation of DocuWare Fulltext Search server through 6.11 allows remote users to connect to and download ... |
| CVE-2017-16919 | — | — | 0.8% | Nov 21, 2017 | MapOS 3.1.11 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in /clientes/visualizar, which allows rem... |
| CVE-2017-16840 | CRITICAL | 9.8 | 3.3% | Nov 21, 2017 | The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bo... |
| CVE-2017-2919 | HIGH | 7.8 | 2.1% | Nov 20, 2017 | An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A speciall... |
| CVE-2017-2897 | HIGH | 7.8 | 2.1% | Nov 20, 2017 | An exploitable out-of-bounds write vulnerability exists in the read_MSAT function of libxls 1.4. A specially crafted XLS... |
| CVE-2017-2896 | HIGH | 7.8 | 2.1% | Nov 20, 2017 | An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially cra... |
| CVE-2017-12111 | HIGH | 8.8 | 2.1% | Nov 20, 2017 | An exploitable out-of-bounds vulnerability exists in the xls_addCell function of libxls 1.4. A specially crafted XLS fil... |
| CVE-2017-12110 | HIGH | 8.8 | 2.1% | Nov 20, 2017 | An exploitable integer overflow vulnerability exists in the xls_appendSST function of libxls 1.4.A specially crafted XLS... |
| CVE-2017-3157 | — | — | 3.1% | Nov 20, 2017 | By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that a... |
| CVE-2017-16908 | — | — | 1.8% | Nov 20, 2017 | In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for ... |
| CVE-2017-16907 | — | — | 1.1% | Nov 20, 2017 | In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action. |
| CVE-2017-16906 | — | — | 1.1% | Nov 20, 2017 | In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action. |
| CVE-2017-12608 | HIGH | 7.8 | 2.9% | Nov 20, 2017 | A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, all... |
| CVE-2017-16904 | — | — | 0.7% | Nov 20, 2017 | The Public tologin feature in admin.php in LvyeCMS through 3.1 allows XSS via a crafted username that is mishandled duri... |
| CVE-2017-16903 | — | — | 2.0% | Nov 20, 2017 | LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences i... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now