2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12579 | — | — | 1.5% | Oct 19, 2017 | An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and ear... |
| CVE-2017-3883 | — | — | 4.5% | Oct 19, 2017 | A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible ... |
| CVE-2017-15612 | — | — | 0.9% | Oct 19, 2017 | mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, ... |
| CVE-2017-15611 | — | — | 0.7% | Oct 19, 2017 | In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserI... |
| CVE-2017-15610 | — | — | 0.6% | Oct 19, 2017 | An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPr... |
| CVE-2017-15609 | — | — | 0.8% | Oct 19, 2017 | Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in cert... |
| CVE-2017-12301 | — | — | 0.4% | Oct 19, 2017 | A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker t... |
| CVE-2017-12298 | — | — | 1.2% | Oct 19, 2017 | A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site sc... |
| CVE-2017-12296 | — | — | 1.2% | Oct 19, 2017 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site s... |
| CVE-2017-12293 | — | — | 2.3% | Oct 19, 2017 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of serv... |
| CVE-2017-12289 | — | — | 0.4% | Oct 19, 2017 | A vulnerability in conditional, verbose debug logging for the IPsec feature of Cisco IOS XE Software could allow an auth... |
| CVE-2017-12288 | — | — | 1.2% | Oct 19, 2017 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthentic... |
| CVE-2017-12287 | — | — | 1.6% | Oct 19, 2017 | A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePre... |
| CVE-2017-12286 | — | — | 0.4% | Oct 19, 2017 | A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profi... |
| CVE-2017-12285 | — | — | 37.2% | Oct 19, 2017 | A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote at... |
| CVE-2017-12284 | — | — | 0.4% | Oct 19, 2017 | A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to ... |
| CVE-2017-12272 | — | — | 1.2% | Oct 19, 2017 | A vulnerability in the web framework code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to co... |
| CVE-2017-12271 | HIGH | 8.8 | 0.7% | Oct 19, 2017 | A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute u... |
| CVE-2017-12260 | — | — | 2.3% | Oct 19, 2017 | A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA50x,... |
| CVE-2017-12259 | — | — | 2.3% | Oct 19, 2017 | A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x ... |
| CVE-2017-12251 | — | — | 2.2% | Oct 19, 2017 | A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote ... |
| CVE-2017-15602 | — | — | 1.5% | Oct 18, 2017 | In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method fu... |
| CVE-2017-15601 | — | — | 1.6% | Oct 18, 2017 | In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/p... |
| CVE-2017-15600 | — | — | 2.1% | Oct 18, 2017 | In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf... |
| CVE-2017-15359 | — | — | 6.2% | Oct 18, 2017 | In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory t... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now