2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14866 | — | — | 0.8% | Sep 29, 2017 | There is a heap-based buffer overflow in the Exiv2::s2Data function of types.cpp in Exiv2 0.26. A Crafted input will lea... |
| CVE-2017-14865 | — | — | 0.8% | Sep 29, 2017 | There is a heap-based buffer overflow in the Exiv2::us2Data function of types.cpp in Exiv2 0.26. A Crafted input will le... |
| CVE-2017-14864 | MEDIUM | 5.5 | 1.1% | Sep 29, 2017 | An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability ca... |
| CVE-2017-14863 | — | — | 0.9% | Sep 29, 2017 | A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerabili... |
| CVE-2017-14862 | MEDIUM | 5.5 | 1.1% | Sep 29, 2017 | An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerabi... |
| CVE-2017-14861 | — | — | 1.0% | Sep 29, 2017 | There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A C... |
| CVE-2017-14860 | — | — | 0.8% | Sep 29, 2017 | There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Cr... |
| CVE-2017-14859 | MEDIUM | 5.5 | 1.1% | Sep 29, 2017 | An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vul... |
| CVE-2017-14858 | — | — | 0.8% | Sep 29, 2017 | There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lea... |
| CVE-2017-14857 | — | — | 0.8% | Sep 29, 2017 | In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted in... |
| CVE-2017-14507 | — | — | 5.2% | Sep 29, 2017 | Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to exec... |
| CVE-2017-12240 | CRITICAL | 9.8 | 13.5% | Sep 29, 2017 | The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could al... |
| CVE-2017-12239 | MEDIUM | 6.8 | 0.4% | Sep 29, 2017 | A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Ci... |
| CVE-2017-12238 | MEDIUM | 6.5 | 2.0% | Sep 29, 2017 | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Se... |
| CVE-2017-12237 | HIGH | 7.5 | 6.9% | Sep 29, 2017 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.... |
| CVE-2017-12236 | — | — | 3.1% | Sep 29, 2017 | A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 coul... |
| CVE-2017-12235 | HIGH | 7.5 | 6.9% | Sep 29, 2017 | A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 t... |
| CVE-2017-12234 | HIGH | 7.5 | 6.9% | Sep 29, 2017 | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through... |
| CVE-2017-12233 | HIGH | 7.5 | 6.9% | Sep 29, 2017 | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through... |
| CVE-2017-12232 | MEDIUM | 6.5 | 2.2% | Sep 29, 2017 | A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers r... |
| CVE-2017-12231 | HIGH | 7.5 | 6.9% | Sep 29, 2017 | A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 ... |
| CVE-2017-12230 | — | — | 3.2% | Sep 29, 2017 | A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attac... |
| CVE-2017-12229 | — | — | 5.1% | Sep 29, 2017 | A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an... |
| CVE-2017-12228 | — | — | 1.0% | Sep 29, 2017 | A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 throu... |
| CVE-2017-12226 | — | — | 3.2% | Sep 29, 2017 | A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controller... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now