2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-15527Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a t...
CVE-2017-12607HIGH7.8A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to cra...
CVE-2017-16902On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or logi...
CVE-2017-16899An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack o...
CVE-2017-9806HIGH7.8A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, all...
CVE-2017-16898The printMP3Headers function in util/listmp3.c in libming v0.4.8 or earlier is vulnerable to a global buffer overflow, w...
CVE-2017-16896A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login par...
CVE-2017-16544HIGH8.8In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used...
CVE-2017-11402An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Design flaws in OP...
CVE-2017-11401An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Improper handling ...
CVE-2017-11400An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. An incomplete firm...
CVE-2017-15110In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participa...
CVE-2017-16894In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo...
CVE-2017-16892In Bftpd before 4.7, there is a memory leak in the file rename function.
CVE-2017-16883The outputSWF_TEXT_RECORD function in util/outputscript.c in libming <= 0.4.8 is vulnerable to a NULL pointer dereferenc...
CVE-2017-16882Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file i...
CVE-2017-16881b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL...
CVE-2017-14077HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message b...
CVE-2017-16566CRITICAL9.8On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attack...
CVE-2017-1000221In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules...
CVE-2017-1000217Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media...
CVE-2017-1000128Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser
CVE-2017-1000127Exiv2 0.26 contains a heap buffer overflow in tiff parser
CVE-2017-1000126exiv2 0.26 contains a Stack out of bounds read in webp parser
CVE-2017-4939VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loade...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now