2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14635 | — | — | 1.9% | Sep 21, 2017 | In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated... |
| CVE-2017-14246 | — | — | 2.2% | Sep 21, 2017 | An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or i... |
| CVE-2017-14245 | — | — | 2.0% | Sep 21, 2017 | An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or i... |
| CVE-2017-14634 | — | — | 2.1% | Sep 21, 2017 | In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS... |
| CVE-2017-14633 | MEDIUM | 6.5 | 1.9% | Sep 21, 2017 | In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapp... |
| CVE-2017-14632 | CRITICAL | 9.8 | 5.7% | Sep 21, 2017 | Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_... |
| CVE-2017-14631 | — | — | 1.6% | Sep 21, 2017 | In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer... |
| CVE-2017-14630 | — | — | 1.7% | Sep 21, 2017 | In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid... |
| CVE-2017-14629 | — | — | 1.4% | Sep 21, 2017 | In sam2p 0.49.3, the in_xpm_reader function in in_xpm.cpp has an integer signedness error, leading to a crash when writi... |
| CVE-2017-14628 | — | — | 1.6% | Sep 21, 2017 | In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp. |
| CVE-2017-6720 | MEDIUM | 6.5 | 1.4% | Sep 21, 2017 | A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an aut... |
| CVE-2017-14626 | — | — | 2.6% | Sep 21, 2017 | ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_decode in coders/sixel.c. |
| CVE-2017-14625 | — | — | 3.2% | Sep 21, 2017 | ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_create in coders/sixel... |
| CVE-2017-14624 | — | — | 3.2% | Sep 21, 2017 | ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function PostscriptDelegateMessage in coders... |
| CVE-2017-12255 | — | — | 0.4% | Sep 21, 2017 | A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell acce... |
| CVE-2017-12254 | — | — | 2.3% | Sep 21, 2017 | A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacke... |
| CVE-2017-12253 | — | — | 1.2% | Sep 21, 2017 | A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwa... |
| CVE-2017-12252 | — | — | 0.4% | Sep 21, 2017 | A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a ... |
| CVE-2017-12250 | — | — | 3.1% | Sep 21, 2017 | A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated... |
| CVE-2017-12248 | — | — | 1.7% | Sep 21, 2017 | A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, ... |
| CVE-2017-12219 | — | — | 2.7% | Sep 21, 2017 | A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones... |
| CVE-2017-12215 | — | — | 1.7% | Sep 21, 2017 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance ... |
| CVE-2017-12214 | — | — | 2.2% | Sep 21, 2017 | A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality f... |
| CVE-2017-14623 | HIGH | 8.1 | 1.7% | Sep 20, 2017 | In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This... |
| CVE-2017-14621 | — | — | 0.6% | Sep 20, 2017 | Portus 2.2.0 has XSS via the Team field, related to typeahead. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now