Skip to main content

Year archive

CVEs published in 2017

Archive summary

14,642 CVEs published in 2017 — 2,108 Critical, 6,607 High, 5,693 Medium, 234 Low, 0 Unrated.

CVE-2017-18004

Published Dec 31, 2017

Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18001

Published Dec 31, 2017

Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain re…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10704

Published Dec 30, 2017

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17089

Published Dec 30, 2017

custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14855

Published Dec 30, 2017

Red Lion HMI panels allow remote attackers to cause a denial of service (software exception) via an HTTP POST request to a long URI that does not exist, as demonstrated by version…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17997

Published Dec 30, 2017

In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addressed in epan/dissectors/packet-mrdisc.c by validating an IPv4 address. This vuln…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 14,642 CVEsPage 1 of 586