2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-11253 | CRITICAL | 9.8 | 6.2% | May 19, 2018 | Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11... |
| CVE-2017-11250 | CRITICAL | 9.8 | 6.2% | May 19, 2018 | Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11... |
| CVE-2017-11240 | CRITICAL | 9.8 | 6.2% | May 19, 2018 | Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11... |
| CVE-2017-18273 | — | — | 2.4% | May 18, 2018 | In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in ... |
| CVE-2017-18272 | — | — | 1.2% | May 18, 2018 | In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-25, there is a use-after-free in ReadOneMNGImage in coders/png.c, which allow... |
| CVE-2017-18271 | — | — | 2.2% | May 18, 2018 | In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in... |
| CVE-2017-18270 | — | — | 0.4% | May 18, 2018 | In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwan... |
| CVE-2017-18269 | — | — | 4.8% | May 18, 2018 | An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Li... |
| CVE-2017-9637 | — | — | 0.2% | May 18, 2018 | Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity... |
| CVE-2017-9635 | — | — | 0.2% | May 18, 2018 | Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are c... |
| CVE-2017-15855 | — | — | 0.2% | May 17, 2018 | In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kern... |
| CVE-2017-18268 | MEDIUM | 5.9 | 1.6% | May 17, 2018 | Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote... |
| CVE-2017-15533 | — | — | 1.9% | May 17, 2018 | Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the R... |
| CVE-2017-17689 | — | — | 4.2% | May 16, 2018 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to pla... |
| CVE-2017-17688 | — | — | 5.6% | May 16, 2018 | The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to pla... |
| CVE-2017-2613 | MEDIUM | 5.4 | 1.7% | May 15, 2018 | jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record w... |
| CVE-2017-2610 | MEDIUM | 5.4 | 1.5% | May 15, 2018 | jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to impr... |
| CVE-2017-2604 | MEDIUM | 4.3 | 1.4% | May 15, 2018 | In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not ... |
| CVE-2017-2603 | LOW | 2.6 | 1.1% | May 15, 2018 | Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This coul... |
| CVE-2017-2602 | LOW | 3.1 | 1.6% | May 15, 2018 | jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the age... |
| CVE-2017-2612 | MEDIUM | 5.4 | 1.6% | May 15, 2018 | In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392... |
| CVE-2017-2608 | HIGH | 8.8 | 6.3% | May 15, 2018 | Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserializatio... |
| CVE-2017-2600 | MEDIUM | 4.3 | 1.1% | May 15, 2018 | In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. The... |
| CVE-2017-2815 | HIGH | 8.1 | 0.9% | May 15, 2018 | An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafte... |
| CVE-2017-14439 | HIGH | 7.5 | 1.7% | May 14, 2018 | Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now