2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1000211 | — | — | 1.7% | Nov 17, 2017 | Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTM... |
| CVE-2017-1000206 | — | — | 2.0% | Nov 17, 2017 | samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in p... |
| CVE-2017-1000203 | — | — | 3.9% | Nov 17, 2017 | ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon result... |
| CVE-2017-4938 | — | — | 0.4% | Nov 17, 2017 | VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulne... |
| CVE-2017-4937 | — | — | 0.4% | Nov 17, 2017 | VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds ... |
| CVE-2017-4936 | — | — | 0.4% | Nov 17, 2017 | VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds ... |
| CVE-2017-4935 | — | — | 0.4% | Nov 17, 2017 | VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds ... |
| CVE-2017-4934 | — | — | 0.4% | Nov 17, 2017 | VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VM... |
| CVE-2017-4929 | — | — | 1.0% | Nov 17, 2017 | VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which m... |
| CVE-2017-4928 | — | — | 1.2% | Nov 17, 2017 | The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere ... |
| CVE-2017-4927 | — | — | 2.3% | Nov 17, 2017 | VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP ne... |
| CVE-2017-10890 | — | — | 0.4% | Nov 17, 2017 | Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.... |
| CVE-2017-10889 | — | — | 1.1% | Nov 17, 2017 | TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vector... |
| CVE-2017-10888 | — | — | 0.9% | Nov 17, 2017 | BOOK WALKER for Windows Ver.1.2.9 and earlier, BOOK WALKER for Mac Ver.1.2.5 and earlier allow an attacker to access loc... |
| CVE-2017-10887 | — | — | 1.1% | Nov 17, 2017 | Untrusted search path vulnerability in BOOK WALKER for Windows Ver.1.2.9 and earlier allows an attacker to gain privileg... |
| CVE-2017-10886 | — | — | 0.5% | Nov 17, 2017 | Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multiv... |
| CVE-2017-16872 | — | — | 3.4% | Nov 17, 2017 | An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fiel... |
| CVE-2017-16871 | — | — | 1.6% | Nov 17, 2017 | The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action functi... |
| CVE-2017-16870 | — | — | 1.0% | Nov 17, 2017 | The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugin... |
| CVE-2017-16869 | — | — | 1.0% | Nov 17, 2017 | p_mach.cpp in UPX 3.94 allows remote attackers to cause a denial of service (invalid memory access and application crash... |
| CVE-2017-16868 | — | — | 1.0% | Nov 17, 2017 | In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a mallo... |
| CVE-2017-1000229 | — | — | 2.0% | Nov 17, 2017 | Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or ca... |
| CVE-2017-1000226 | — | — | 1.4% | Nov 17, 2017 | Stop User Enumeration 1.3.8 allows user enumeration via the REST API |
| CVE-2017-1000225 | — | — | 0.7% | Nov 17, 2017 | Reflected XSS in Relevanssi Premium version 1.14.8 when using relevanssi_didyoumean() could allow unauthenticated attack... |
| CVE-2017-1000223 | — | — | 0.5% | Nov 17, 2017 | A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlie... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now