2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-18285 | — | — | 0.3% | Jun 4, 2018 | The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might a... |
| CVE-2017-18284 | — | — | 0.3% | Jun 4, 2018 | The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which... |
| CVE-2017-2860 | HIGH | 7.5 | 1.4% | Jun 1, 2018 | An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek Neuro... |
| CVE-2017-2858 | HIGH | 7.5 | 1.6% | Jun 1, 2018 | An exploitable denial-of-service vulnerability exists in the traversal of lists functionality of Natus Xltek NeuroWorks ... |
| CVE-2017-2852 | HIGH | 7.5 | 1.4% | Jun 1, 2018 | An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek Neuro... |
| CVE-2017-6153 | — | — | 1.7% | Jun 1, 2018 | Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes i... |
| CVE-2017-17171 | — | — | 0.5% | Jun 1, 2018 | Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious para... |
| CVE-2017-16153 | — | — | 1.8% | May 29, 2018 | gaoxuyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in t... |
| CVE-2017-16062 | HIGH | 7.5 | 1.1% | May 29, 2018 | node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished b... |
| CVE-2017-16061 | — | — | 1.1% | May 29, 2018 | tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm... |
| CVE-2017-16047 | — | — | 1.3% | May 29, 2018 | mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm... |
| CVE-2017-16010 | — | — | 1.0% | May 29, 2018 | i18next is a language translation framework. When using the .init method, passing interpolation options without passing ... |
| CVE-2017-16003 | — | — | 2.3% | May 29, 2018 | windows-build-tools is a module for installing C++ Build Tools for Windows using npm. windows-build-tools versions below... |
| CVE-2017-1768 | MEDIUM | 4.3 | 1.4% | May 29, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information ... |
| CVE-2017-14185 | — | — | 1.3% | May 25, 2018 | An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows S... |
| CVE-2017-9641 | — | — | 0.9% | May 25, 2018 | PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft... |
| CVE-2017-1752 | — | — | 1.6% | May 25, 2018 | IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IB... |
| CVE-2017-3961 | LOW | 3.5 | 0.6% | May 25, 2018 | Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.4... |
| CVE-2017-9664 | — | — | 2.7% | May 24, 2018 | In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to ... |
| CVE-2017-14187 | — | — | 0.5% | May 24, 2018 | A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, ... |
| CVE-2017-17315 | — | — | 1.2% | May 24, 2018 | Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; ... |
| CVE-2017-17158 | — | — | 0.3% | May 24, 2018 | Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the ver... |
| CVE-2017-9421 | — | — | 1.1% | May 24, 2018 | Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain ... |
| CVE-2017-9317 | — | — | 1.0% | May 23, 2018 | Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can g... |
| CVE-2017-2598 | MEDIUM | 4.3 | 1.1% | May 23, 2018 | Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkin... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now