2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-3887 | MEDIUM | 5.9 | 1.3% | Apr 7, 2017 | A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Softw... |
| CVE-2017-0888 | MEDIUM | 4.3 | 1.5% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navi... |
| CVE-2017-0887 | MEDIUM | 4.3 | 0.9% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing ... |
| CVE-2017-0886 | MEDIUM | 6.5 | 1.2% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application lo... |
| CVE-2017-0885 | MEDIUM | 4.3 | 0.9% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share.... |
| CVE-2017-0884 | MEDIUM | 4.3 | 0.7% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permis... |
| CVE-2017-7306 | MEDIUM | 6.4 | 0.4% | Apr 4, 2017 | Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proxi... |
| CVE-2017-7305 | MEDIUM | 4.6 | 0.3% | Apr 4, 2017 | Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attac... |
| CVE-2017-7389 | MEDIUM | 6.1 | 0.8% | Apr 1, 2017 | Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insu... |
| CVE-2017-7388 | MEDIUM | 6.1 | 0.8% | Apr 1, 2017 | A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtrat... |
| CVE-2017-7320 | MEDIUM | 6.1 | 0.9% | Mar 30, 2017 | setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language paramete... |
| CVE-2017-5973 | MEDIUM | 5.5 | 0.5% | Mar 27, 2017 | The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to... |
| CVE-2017-7264 | MEDIUM | 5.3 | 1.4% | Mar 26, 2017 | Use-after-free vulnerability in the fz_subsample_pixmap function in fitz/pixmap.c in Artifex MuPDF 1.10a allows remote a... |
| CVE-2017-7251 | MEDIUM | 6.1 | 1.0% | Mar 23, 2017 | A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtrati... |
| CVE-2017-6836 | MEDIUM | 5.5 | 2.9% | Mar 20, 2017 | Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Li... |
| CVE-2017-6834 | MEDIUM | 5.5 | 2.6% | Mar 20, 2017 | Heap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.... |
| CVE-2017-6832 | MEDIUM | 5.5 | 3.0% | Mar 20, 2017 | Heap-based buffer overflow in the decodeBlock in MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, ... |
| CVE-2017-6831 | MEDIUM | 5.5 | 3.1% | Mar 20, 2017 | Heap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5... |
| CVE-2017-6356 | MEDIUM | 5.3 | 1.0% | Mar 20, 2017 | Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified... |
| CVE-2017-5987 | MEDIUM | 5.5 | 0.4% | Mar 20, 2017 | The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privil... |
| CVE-2017-6958 | MEDIUM | 6.1 | 0.6% | Mar 17, 2017 | An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to i... |
| CVE-2017-6955 | MEDIUM | 5.3 | 1.8% | Mar 17, 2017 | An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able... |
| CVE-2017-0073 | MEDIUM | 4.3 | 33.4% | Mar 17, 2017 | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W... |
| CVE-2017-0060 | MEDIUM | 5.5 | 15.9% | Mar 17, 2017 | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W... |
| CVE-2017-0059 | MEDIUM | 4.3 | 62.0% | Mar 17, 2017 | Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now