2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-8917SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci...
CVE-2017-4017User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view u...
CVE-2017-4016Web Server method disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers t...
CVE-2017-4015MEDIUM4.5Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated...
CVE-2017-4014Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authe...
CVE-2017-4013Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain pr...
CVE-2017-4012Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authe...
CVE-2017-4011Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x a...
CVE-2017-9031The WebUI component in Deluge before 1.3.15 contains a directory traversal vulnerability involving a request in which th...
CVE-2017-7493HIGH7.8Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable ...
CVE-2017-9030The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a directory traversal attack tha...
CVE-2017-8849smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount hel...
CVE-2017-8422KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and le...
CVE-2017-5215The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a ...
CVE-2017-5214The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value bas...
CVE-2017-9026Stack buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote una...
CVE-2017-9025Heap buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote unau...
CVE-2017-7488Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server...
CVE-2017-7662Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple ...
CVE-2017-7661Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cro...
CVE-2017-6658Cisco Sourcefire Snort 3.0 before build 233 has a Buffer Overread related to use of a decoder array. The size was off by...
CVE-2017-6657Cisco Sourcefire Snort 3.0 before build 233 mishandles Ether Type Validation. Since valid ether type and IP protocol num...
CVE-2017-6651A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that co...
CVE-2017-6079CRITICAL9.8The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-def...
CVE-2017-3882A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could al...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now