2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-5858An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5606MEDIUM5.9An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5605An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5604An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5603An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5602An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5593An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5592MEDIUM5.9An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5591MEDIUM5.9An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5590An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5589An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson...
CVE-2017-5941CRITICAL9.8An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu...
CVE-2017-5940Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its...
CVE-2017-5180Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt ...
CVE-2017-3813A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows c...
CVE-2017-3807A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software,...
CVE-2017-5634The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended...
CVE-2017-5848HIGH7.5The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attack...
CVE-2017-5847HIGH7.5The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allow...
CVE-2017-5846The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer befor...
CVE-2017-5845The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows rem...
CVE-2017-5844The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3...
CVE-2017-5843Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_...
CVE-2017-5842The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allo...
CVE-2017-5841The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows rem...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now