2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-14635In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated...
CVE-2017-14246An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or i...
CVE-2017-14245An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or i...
CVE-2017-14634In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS...
CVE-2017-14633MEDIUM6.5In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapp...
CVE-2017-14632CRITICAL9.8Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_...
CVE-2017-14631In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer...
CVE-2017-14630In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid...
CVE-2017-14629In sam2p 0.49.3, the in_xpm_reader function in in_xpm.cpp has an integer signedness error, leading to a crash when writi...
CVE-2017-14628In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp.
CVE-2017-6720MEDIUM6.5A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an aut...
CVE-2017-14626ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_decode in coders/sixel.c.
CVE-2017-14625ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_create in coders/sixel...
CVE-2017-14624ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function PostscriptDelegateMessage in coders...
CVE-2017-12255A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell acce...
CVE-2017-12254A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacke...
CVE-2017-12253A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwa...
CVE-2017-12252A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a ...
CVE-2017-12250A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated...
CVE-2017-12248A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, ...
CVE-2017-12219A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones...
CVE-2017-12215A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance ...
CVE-2017-12214A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality f...
CVE-2017-14623HIGH8.1In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This...
CVE-2017-14621Portus 2.2.0 has XSS via the Team field, related to typeahead.

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now