2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-3887MEDIUM5.9A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Softw...
CVE-2017-0888MEDIUM4.3Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navi...
CVE-2017-0887MEDIUM4.3Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing ...
CVE-2017-0886MEDIUM6.5Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application lo...
CVE-2017-0885MEDIUM4.3Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share....
CVE-2017-0884MEDIUM4.3Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permis...
CVE-2017-7306MEDIUM6.4Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proxi...
CVE-2017-7305MEDIUM4.6Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attac...
CVE-2017-7389MEDIUM6.1Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insu...
CVE-2017-7388MEDIUM6.1A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtrat...
CVE-2017-7320MEDIUM6.1setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language paramete...
CVE-2017-5973MEDIUM5.5The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to...
CVE-2017-7264MEDIUM5.3Use-after-free vulnerability in the fz_subsample_pixmap function in fitz/pixmap.c in Artifex MuPDF 1.10a allows remote a...
CVE-2017-7251MEDIUM6.1A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtrati...
CVE-2017-6836MEDIUM5.5Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Li...
CVE-2017-6834MEDIUM5.5Heap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3....
CVE-2017-6832MEDIUM5.5Heap-based buffer overflow in the decodeBlock in MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, ...
CVE-2017-6831MEDIUM5.5Heap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5...
CVE-2017-6356MEDIUM5.3Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified...
CVE-2017-5987MEDIUM5.5The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privil...
CVE-2017-6958MEDIUM6.1An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to i...
CVE-2017-6955MEDIUM5.3An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able...
CVE-2017-0073MEDIUM4.3The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W...
CVE-2017-0060MEDIUM5.5The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W...
CVE-2017-0059MEDIUM4.3Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now