2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12579An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and ear...
CVE-2017-3883A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible ...
CVE-2017-15612mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, ...
CVE-2017-15611In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserI...
CVE-2017-15610An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPr...
CVE-2017-15609Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in cert...
CVE-2017-12301A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker t...
CVE-2017-12298A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site sc...
CVE-2017-12296A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site s...
CVE-2017-12293A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of serv...
CVE-2017-12289A vulnerability in conditional, verbose debug logging for the IPsec feature of Cisco IOS XE Software could allow an auth...
CVE-2017-12288A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthentic...
CVE-2017-12287A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePre...
CVE-2017-12286A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profi...
CVE-2017-12285A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote at...
CVE-2017-12284A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to ...
CVE-2017-12272A vulnerability in the web framework code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to co...
CVE-2017-12271HIGH8.8A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute u...
CVE-2017-12260A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA50x,...
CVE-2017-12259A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x ...
CVE-2017-12251A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote ...
CVE-2017-15602In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method fu...
CVE-2017-15601In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/p...
CVE-2017-15600In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf...
CVE-2017-15359In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory t...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now