CVE-2017-20187

2026-03-05T14:19:05Z2a43554a782f6252a34c27901c66baaa669781c35cb8cfeb81e249bbb3c081de
authentication-bypassbcryptbitrixdenial-of-serviceheap-overflowivantikube-apiserverkuberneteslinux-kernelout-of-boundsphpprivilege-escalationsql-injectionsymlink-attacktemporary-fileuse-after-freeweb-pluginsxss

What happened

NVD RSS feed containing multiple vulnerabilities across server, kernel, web application and device software. Notable issues include critical improper-access controls in Vaerys-Dawn (CVE-2018-25092, CVE-2018-25093), multiple Linux kernel use-after-free / OOB flaws that can cause DoS or potential privilege escalation (CVE-2023-1192, CVE-2023-1193, CVE-2023-1194, CVE-2023-1476), a kube-apiserver aggregated-API redirect that may leak credentials (CVE-2022-3172), Ivanti local privilege escalation via missing authentication (CVE-2022-43554, CVE-2022-43555), PHP heap overflow via CLI server workers (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
nist_nvd_cve_rss
Record identifier
2a43554a782f6252a34c27901c66baaa669781c35cb8cfeb81e249bbb3c081de
Enrichment time
2026-03-05T14:19:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2017-20187 · Baitaphish