CVE-2017-20187
2026-03-05T14:19:05Z•2a43554a782f6252a34c27901c66baaa669781c35cb8cfeb81e249bbb3c081de
authentication-bypassbcryptbitrixdenial-of-serviceheap-overflowivantikube-apiserverkuberneteslinux-kernelout-of-boundsphpprivilege-escalationsql-injectionsymlink-attacktemporary-fileuse-after-freeweb-pluginsxss
What happened
NVD RSS feed containing multiple vulnerabilities across server, kernel, web application and device software. Notable issues include critical improper-access controls in Vaerys-Dawn (CVE-2018-25092, CVE-2018-25093), multiple Linux kernel use-after-free / OOB flaws that can cause DoS or potential privilege escalation (CVE-2023-1192, CVE-2023-1193, CVE-2023-1194, CVE-2023-1476), a kube-apiserver aggregated-API redirect that may leak credentials (CVE-2022-3172), Ivanti local privilege escalation via missing authentication (CVE-2022-43554, CVE-2022-43555), PHP heap overflow via CLI server workers (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- nist_nvd_cve_rss
- Record identifier
- 2a43554a782f6252a34c27901c66baaa669781c35cb8cfeb81e249bbb3c081de
- Enrichment time
- 2026-03-05T14:19:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.