2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8917 | — | — | 99.8% | May 17, 2017 | SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci... |
| CVE-2017-4017 | — | — | 1.0% | May 17, 2017 | User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view u... |
| CVE-2017-4016 | — | — | 1.0% | May 17, 2017 | Web Server method disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers t... |
| CVE-2017-4015 | MEDIUM | 4.5 | 1.1% | May 17, 2017 | Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated... |
| CVE-2017-4014 | — | — | 0.9% | May 17, 2017 | Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authe... |
| CVE-2017-4013 | — | — | 1.0% | May 17, 2017 | Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain pr... |
| CVE-2017-4012 | — | — | 1.3% | May 17, 2017 | Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authe... |
| CVE-2017-4011 | — | — | 3.3% | May 17, 2017 | Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x a... |
| CVE-2017-9031 | — | — | 2.5% | May 17, 2017 | The WebUI component in Deluge before 1.3.15 contains a directory traversal vulnerability involving a request in which th... |
| CVE-2017-7493 | HIGH | 7.8 | 0.4% | May 17, 2017 | Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable ... |
| CVE-2017-9030 | — | — | 2.1% | May 17, 2017 | The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a directory traversal attack tha... |
| CVE-2017-8849 | — | — | 1.9% | May 17, 2017 | smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount hel... |
| CVE-2017-8422 | — | — | 1.8% | May 17, 2017 | KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and le... |
| CVE-2017-5215 | — | — | 3.6% | May 17, 2017 | The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a ... |
| CVE-2017-5214 | — | — | 1.2% | May 17, 2017 | The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value bas... |
| CVE-2017-9026 | — | — | 1.6% | May 17, 2017 | Stack buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote una... |
| CVE-2017-9025 | — | — | 1.6% | May 17, 2017 | Heap buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote unau... |
| CVE-2017-7488 | — | — | 1.4% | May 16, 2017 | Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server... |
| CVE-2017-7662 | — | — | 1.1% | May 16, 2017 | Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple ... |
| CVE-2017-7661 | — | — | 1.1% | May 16, 2017 | Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cro... |
| CVE-2017-6658 | — | — | 1.1% | May 16, 2017 | Cisco Sourcefire Snort 3.0 before build 233 has a Buffer Overread related to use of a decoder array. The size was off by... |
| CVE-2017-6657 | — | — | 1.1% | May 16, 2017 | Cisco Sourcefire Snort 3.0 before build 233 mishandles Ether Type Validation. Since valid ether type and IP protocol num... |
| CVE-2017-6651 | — | — | 2.0% | May 16, 2017 | A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that co... |
| CVE-2017-6079 | CRITICAL | 9.8 | 46.8% | May 16, 2017 | The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-def... |
| CVE-2017-3882 | — | — | 1.8% | May 16, 2017 | A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could al... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now