2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-10604 | MEDIUM | 5.3 | 0.9% | Jul 17, 2017 | When the device is configured to perform account lockout with a defined period of time, any unauthenticated user attempt... |
| CVE-2017-1000078 | MEDIUM | 6.1 | 0.7% | Jul 17, 2017 | Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration |
| CVE-2017-1000043 | MEDIUM | 6.1 | 0.9% | Jul 17, 2017 | Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain ... |
| CVE-2017-1321 | MEDIUM | 6.1 | 1.0% | Jul 12, 2017 | IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2017-11189 | MEDIUM | 6.5 | 1.3% | Jul 12, 2017 | unrarlib.c in unrar-free 0.0.1 might allow remote attackers to cause a denial of service (NULL pointer dereference and a... |
| CVE-2017-11107 | MEDIUM | 6.1 | 2.1% | Jul 8, 2017 | phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter. |
| CVE-2017-11104 | MEDIUM | 5.9 | 2.7% | Jul 8, 2017 | Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an... |
| CVE-2017-2245 | MEDIUM | 5 | 2.6% | Jul 7, 2017 | Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitra... |
| CVE-2017-2239 | MEDIUM | 5.3 | 0.5% | Jul 7, 2017 | Marp versions v0.0.10 and earlier may allow an attacker to access local resources and files using JavaScript. |
| CVE-2017-10796 | MEDIUM | 6.5 | 0.9% | Jul 2, 2017 | On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authenticatio... |
| CVE-2017-2298 | MEDIUM | 6.5 | 1.5% | Jun 30, 2017 | The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path wher... |
| CVE-2017-6030 | MEDIUM | 6.5 | 2.1% | Jun 30, 2017 | A predictable value range from previous values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, fir... |
| CVE-2017-5529 | MEDIUM | 4.1 | 1.3% | Jun 29, 2017 | JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theore... |
| CVE-2017-10673 | MEDIUM | 6.1 | 0.7% | Jun 29, 2017 | admin/profile.php in GetSimple CMS 3.x has XSS in a name field. |
| CVE-2017-9998 | MEDIUM | 6.5 | 2.0% | Jun 28, 2017 | The _dwarf_decode_s_leb128_chk function in dwarf_leb.c in libdwarf through 2017-06-28 allows remote attackers to cause a... |
| CVE-2017-9929 | MEDIUM | 5.5 | — | Jun 26, 2017 | In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers t... |
| CVE-2017-9928 | MEDIUM | 5.5 | — | Jun 26, 2017 | In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to... |
| CVE-2017-2782 | MEDIUM | 6.5 | 1.0% | Jun 22, 2017 | An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.... |
| CVE-2017-1304 | MEDIUM | 6.2 | 0.4% | Jun 21, 2017 | IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storag... |
| CVE-2017-2829 | MEDIUM | 6.5 | 2.9% | Jun 21, 2017 | An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam C1 Indoor HD ... |
| CVE-2017-9130 | MEDIUM | 5.5 | 2.9% | Jun 21, 2017 | The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to caus... |
| CVE-2017-1000369 | MEDIUM | 4 | 0.5% | Jun 19, 2017 | Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunc... |
| CVE-2017-9503 | MEDIUM | 5.5 | 0.4% | Jun 16, 2017 | QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest O... |
| CVE-2017-9375 | MEDIUM | 5.5 | 0.4% | Jun 16, 2017 | QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users ... |
| CVE-2017-9374 | MEDIUM | 5.5 | 0.4% | Jun 16, 2017 | Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged u... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now