2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-9615Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all ...
CVE-2017-9466The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use o...
CVE-2017-7459ntopng before 3.0 allows HTTP Response Splitting.
CVE-2017-7416ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
CVE-2017-6678A vulnerability in the ingress UDP packet processing functionality of Cisco Virtualized Packet Core-Distributed Instance...
CVE-2017-6669HIGH7.8Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Network Recording Player for Advanced Recording Format...
CVE-2017-6662A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Mana...
CVE-2017-9872The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, ...
CVE-2017-9871The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows re...
CVE-2017-9870The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows re...
CVE-2017-9869The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows rem...
CVE-2017-9868In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obta...
CVE-2017-9865The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of ser...
CVE-2017-9840Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbi...
CVE-2017-9848SQL injection vulnerability in C_InfoService.asmx in WebServices in Easysite 7.0 could allow remote attackers to execute...
CVE-2017-9847The bdecode function in bdecode.cpp in libtorrent 1.1.3 allows remote attackers to cause a denial of service (heap-based...
CVE-2017-9846HIGH8.8Winmail Server 6.1 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php...
CVE-2017-9837Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2017-9836Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary ...
CVE-2017-9833HIGH7.5/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read ...
CVE-2017-9832An integer overflow vulnerability in ptp-pack.c (ptp_unpack_OPL function) of libmtp (version 1.1.12 and below) allows at...
CVE-2017-9831An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version ...
CVE-2017-9829'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allow...
CVE-2017-9828'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command...
CVE-2017-9772Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with rais...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now