2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-6472In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injectio...
CVE-2017-6471In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malfor...
CVE-2017-6470In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malf...
CVE-2017-6469In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an LDSS dissector crash, triggered by packet injection or a ma...
CVE-2017-6468In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser crash, triggered by a malformed captur...
CVE-2017-6467In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parser infinite loop, triggered by a malforme...
CVE-2017-5867ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticate...
CVE-2017-5866The autocomplete feature in the E-Mail share dialog in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9...
CVE-2017-5865The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x bef...
CVE-2017-5836The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors in...
CVE-2017-5835libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offs...
CVE-2017-5834The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap r...
CVE-2017-5833Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver bef...
CVE-2017-5832Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arb...
CVE-2017-5831Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new pass...
CVE-2017-5830Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies relate...
CVE-2017-5616Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script ...
CVE-2017-5615cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
CVE-2017-5614MEDIUM6.1Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and...
CVE-2017-5613Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string ...
CVE-2017-5571Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and...
CVE-2017-5356Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string con...
CVE-2017-5196Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via vecto...
CVE-2017-5195Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a cra...
CVE-2017-5194Use-after-free vulnerability in Irssi before 0.8.21 allows remote attackers to cause a denial of service (crash) via an ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now