2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-3815An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to ...
CVE-2017-3811An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to hav...
CVE-2017-6880Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or p...
CVE-2017-6370TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote...
CVE-2017-6969readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The ...
CVE-2017-6967HIGH7.3xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not bein...
CVE-2017-6966readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, reloca...
CVE-2017-6965readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-differen...
CVE-2017-6962An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer overflow. This is...
CVE-2017-6961An issue was discovered in apng2gif 1.7. There is improper sanitization of user input causing huge memory allocations, r...
CVE-2017-6960HIGH7.5An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, relate...
CVE-2017-6958MEDIUM6.1An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to i...
CVE-2017-6955MEDIUM5.3An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able...
CVE-2017-6954An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possib...
CVE-2017-0154Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain polic...
CVE-2017-0151A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object...
CVE-2017-0150A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object...
CVE-2017-0149HIGH8.8Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (...
CVE-2017-0148HIGH8.1The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows...
CVE-2017-0147HIGH7.5The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows...
CVE-2017-0146HIGH8.8The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows...
CVE-2017-0145HIGH8.8The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows...
CVE-2017-0144HIGH8.8The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows...
CVE-2017-0143HIGH8.8The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows...
CVE-2017-0141A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now