2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16754 | — | — | 1.8% | Nov 10, 2017 | Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php a... |
| CVE-2017-16634 | — | — | 3.9% | Nov 10, 2017 | In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method. |
| CVE-2017-16633 | — | — | 1.5% | Nov 10, 2017 | In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unautho... |
| CVE-2017-16568 | MEDIUM | 5.4 | 2.0% | Nov 10, 2017 | Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality.... |
| CVE-2017-16567 | MEDIUM | 5.4 | 2.2% | Nov 10, 2017 | Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. T... |
| CVE-2017-16562 | — | — | 27.4% | Nov 10, 2017 | The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers... |
| CVE-2017-16249 | — | — | 59.4% | Nov 10, 2017 | The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST requ... |
| CVE-2017-15638 | — | — | 1.2% | Nov 10, 2017 | The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) Desktop 12 SP2, Server 12 SP2, and Server... |
| CVE-2017-12969 | — | — | 10.1% | Nov 10, 2017 | Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows r... |
| CVE-2017-12803 | — | — | 2.2% | Nov 10, 2017 | The Node_ValidatePtr function in corec/corec/node/node.c in mkclean 0.8.9 allows remote attackers to cause a denial of s... |
| CVE-2017-12802 | — | — | 2.4% | Nov 10, 2017 | The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial ... |
| CVE-2017-12801 | — | — | 2.4% | Nov 10, 2017 | The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of ... |
| CVE-2017-12800 | — | — | 2.4% | Nov 10, 2017 | The EBML_FindNextElement function in ebmlmain.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial... |
| CVE-2017-12783 | — | — | 2.4% | Nov 10, 2017 | The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of s... |
| CVE-2017-12782 | — | — | 2.4% | Nov 10, 2017 | The ReadData function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of servic... |
| CVE-2017-12781 | — | — | 2.4% | Nov 10, 2017 | The EBML_BufferToID function in ebmlelement.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial o... |
| CVE-2017-12780 | — | — | 2.4% | Nov 10, 2017 | The ReadData function in ebmlstring.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of servic... |
| CVE-2017-12779 | — | — | 2.2% | Nov 10, 2017 | The Node_GetData function in corec/corec/node/node.c in mkvalidator 0.5.1 allows remote attackers to cause a denial of s... |
| CVE-2017-11461 | — | — | 1.0% | Nov 10, 2017 | NetApp OnCommand Unified Manager for 7-mode (core package) versions prior to 5.2.1 are susceptible to a clickjacking or ... |
| CVE-2017-11309 | — | — | 9.4% | Nov 10, 2017 | Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary co... |
| CVE-2017-16759 | — | — | 2.2% | Nov 9, 2017 | The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/... |
| CVE-2017-16758 | — | — | 1.0% | Nov 9, 2017 | Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed p... |
| CVE-2017-16757 | — | — | 0.4% | Nov 9, 2017 | Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a ... |
| CVE-2017-16711 | — | — | 1.2% | Nov 9, 2017 | The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failur... |
| CVE-2017-16651 | HIGH | 7.8 | 42.8% | Nov 9, 2017 | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now