2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-9338MEDIUM5.4Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10...
CVE-2017-8896ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS o...
CVE-2017-7947NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive passwo...
CVE-2017-6744HIGH8.8The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti...
CVE-2017-6743HIGH8.8The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti...
CVE-2017-6742HIGH8.8A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the aff...
CVE-2017-6741HIGH8.8A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the aff...
CVE-2017-6740HIGH8.8The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti...
CVE-2017-6739HIGH8.8A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the aff...
CVE-2017-6738HIGH8.8The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti...
CVE-2017-6737HIGH8.8A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the aff...
CVE-2017-6736HIGH8.8The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti...
CVE-2017-9639An issue was discovered in Fuji Electric V-Server Version 3.3.22.0 and prior. A memory corruption vulnerability has been...
CVE-2017-3754Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enab...
CVE-2017-3742In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is...
CVE-2017-11399Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg 2.4 through 3.3.2 allows remote attac...
CVE-2017-11128Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.
CVE-2017-11127Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.
CVE-2017-7532In Moodle 3.x, course creators are able to change system default settings for courses.
CVE-2017-7531In Moodle 3.3, the course overview block reveals activities in hidden courses.
CVE-2017-2642Moodle 3.x has user fullname disclosure on the user preferences page.
CVE-2017-11361Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add ro...
CVE-2017-10987An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a...
CVE-2017-10986An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of servi...
CVE-2017-10985An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes"...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now