CVE Database

Comprehensive vulnerability intelligence with advanced analytics

7.5

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP…

Published: Sep 29, 2017
Modified: Jan 12, 2026
EPSS: 6.55%
View Details
7.5

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP…

Published: Sep 29, 2017
Modified: Jan 12, 2026
EPSS: 6.55%
View Details
6.5

CVE-2017-12232

Medium KEV

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to…

Published: Sep 29, 2017
Modified: Jan 12, 2026
EPSS: 0.99%
View Details
7.5

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration,…

Published: Sep 29, 2017
Modified: Oct 22, 2025
EPSS: 6.80%
View Details
7.5

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS)…

Published: Sep 07, 2017
Modified: Oct 22, 2025
Product: cisco ios_xe
EPSS: 10.83%
View Details
9.8

CVE-2017-11357

Critical KEV

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

Published: Aug 23, 2017
Modified: Oct 22, 2025
Product: telerik ui_for_asp.net_ajax
EPSS: 93.84%
View Details
9.8

CVE-2017-11317

Critical KEV

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

Published: Aug 23, 2017
Modified: Oct 22, 2025
Product: telerik ui_for_asp.net_ajax
EPSS: 92.12%
View Details
7.8

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.

Published: Aug 09, 2017
Modified: Oct 22, 2025
Product: intel ethernet_diagnostics_driver_iqvw64.sys
EPSS: 5.71%
View Details
7.5

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.

Published: Aug 07, 2017
Modified: Oct 22, 2025
Product: sap netweaver_application_server_java
EPSS: 93.22%
View Details
6.5

CVE-2017-6663

Medium KEV

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.

Published: Aug 07, 2017
Modified: Oct 22, 2025
Product: cisco ios
EPSS: 2.32%
View Details
8.8

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

Published: Jul 20, 2017
Modified: Oct 22, 2025
Product: dnnsoftware dotnetnuke
EPSS: 94.29%
View Details
8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP…

Published: Jul 17, 2017
Modified: Oct 22, 2025
Product: cisco ios
EPSS: 18.98%
View Details
8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP…

Published: Jul 17, 2017
Modified: Oct 22, 2025
EPSS: 28.84%
View Details
8.8

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.  The vulnerability is due to a buffer overflow…

Published: Jul 17, 2017
Modified: Jan 12, 2026
EPSS: 3.60%
View Details
8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP…

Published: Jul 17, 2017
Modified: Oct 22, 2025
EPSS: 24.27%
View Details
8.8

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.  The vulnerability is due to a buffer overflow…

Published: Jul 17, 2017
Modified: Oct 22, 2025
EPSS: 28.84%
View Details
8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP…

Published: Jul 17, 2017
Modified: Oct 22, 2025
EPSS: 28.84%
View Details
8.8

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.  The vulnerability is due to a buffer overflow…

Published: Jul 17, 2017
Modified: Oct 22, 2025
EPSS: 28.84%
View Details
8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP…

Published: Jul 17, 2017
Modified: Oct 22, 2025
EPSS: 89.02%
View Details
9.8

CVE-2017-8543

Critical KEV

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an…

Published: Jun 15, 2017
Modified: Oct 22, 2025
Product: microsoft windows_10_1607
EPSS: 79.94%
View Details
9.8

CVE-2016-7836

Critical KEV

SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

Published: Jun 09, 2017
Modified: Oct 22, 2025
Product: skygroup skysea_client_view
EPSS: 35.34%
View Details
9.8

CVE-2017-6862

Critical KEV

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.

Published: May 26, 2017
Modified: Oct 22, 2025
EPSS: 49.86%
View Details
7.8

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.

Published: May 12, 2017
Modified: Oct 22, 2025
Product: microsoft office
EPSS: 64.90%
View Details
7.8

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0262 and CVE-2017-0281.

Published: May 12, 2017
Modified: Oct 22, 2025
Product: microsoft office
EPSS: 92.89%
View Details