2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1324 | — | — | 0.7% | Oct 3, 2017 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2017-1311 | — | — | 1.5% | Oct 3, 2017 | IBM Insights Foundation for Energy 2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQ... |
| CVE-2017-12792 | — | — | 1.2% | Oct 3, 2017 | Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authenti... |
| CVE-2017-12639 | — | — | 2.5% | Oct 3, 2017 | Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbit... |
| CVE-2017-12638 | — | — | 2.5% | Oct 3, 2017 | Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbit... |
| CVE-2017-12620 | — | — | 3.0% | Oct 3, 2017 | When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a ... |
| CVE-2017-11498 | — | — | 3.0% | Oct 3, 2017 | Buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LD... |
| CVE-2017-11497 | — | — | 4.8% | Oct 3, 2017 | Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Senti... |
| CVE-2017-11496 | — | — | 4.8% | Oct 3, 2017 | Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Senti... |
| CVE-2017-11322 | — | — | 4.7% | Oct 3, 2017 | The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileg... |
| CVE-2017-11321 | HIGH | 7.2 | 8.3% | Oct 3, 2017 | The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admi... |
| CVE-2017-14977 | — | — | 2.0% | Oct 2, 2017 | The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability... |
| CVE-2017-14976 | — | — | 2.6% | Oct 2, 2017 | The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerabili... |
| CVE-2017-14975 | — | — | 2.5% | Oct 2, 2017 | The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability ... |
| CVE-2017-14974 | — | — | 1.0% | Oct 2, 2017 | The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin... |
| CVE-2017-14970 | — | — | 1.2% | Oct 2, 2017 | In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow g... |
| CVE-2017-14958 | — | — | 1.3% | Oct 2, 2017 | lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP... |
| CVE-2017-14957 | — | — | 1.1% | Oct 2, 2017 | Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to i... |
| CVE-2017-14955 | MEDIUM | 5.9 | 12.1% | Oct 2, 2017 | Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, whi... |
| CVE-2017-14954 | — | — | 1.0% | Oct 2, 2017 | The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in uninten... |
| CVE-2017-14941 | — | — | 1.0% | Oct 2, 2017 | Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticat... |
| CVE-2017-14797 | — | — | 0.4% | Oct 1, 2017 | Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to rea... |
| CVE-2017-9794 | — | — | 1.2% | Sep 30, 2017 | When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh comma... |
| CVE-2017-14947 | — | — | 1.2% | Sep 30, 2017 | Artifex GSView 6.0 Beta on Windows allows attackers to execute arbitrary code or cause a denial of service via a crafted... |
| CVE-2017-14946 | — | — | 0.8% | Sep 30, 2017 | Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impa... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now