2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12312An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an au...
CVE-2017-12311A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to...
CVE-2017-12309A vulnerability in the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a...
CVE-2017-12306A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an u...
CVE-2017-12305A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to exe...
CVE-2017-12304A vulnerability in the IOS daemon (IOSd) web-based management interface of Cisco IOS and IOS XE Software could allow an ...
CVE-2017-12303A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web ...
CVE-2017-12302A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote ...
CVE-2017-12300A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote ...
CVE-2017-12299A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Gene...
CVE-2017-12292Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all...
CVE-2017-12291Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all...
CVE-2017-12290Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all...
CVE-2017-14034The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.7 and other products, miscalculate...
CVE-2017-13136The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL p...
CVE-2017-13135A NULL Pointer Dereference exists in VideoLAN x265, as used in libbpg 0.9.7 and other products, because the CUData::init...
CVE-2017-16842Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin befo...
CVE-2017-16841LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.
CVE-2017-8807CRITICAL9.1vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows r...
CVE-2017-16837Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution...
CVE-2017-16836MEDIUM6.1Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via...
CVE-2017-16834PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depend...
CVE-2017-5533CRITICAL9.3A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition,...
CVE-2017-5532MEDIUM5.4A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edi...
CVE-2017-15115HIGH7.8The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended ne...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now