2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-11253CRITICAL9.8Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11...
CVE-2017-11250CRITICAL9.8Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11...
CVE-2017-11240CRITICAL9.8Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11...
CVE-2017-18273In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in ...
CVE-2017-18272In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-25, there is a use-after-free in ReadOneMNGImage in coders/png.c, which allow...
CVE-2017-18271In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in...
CVE-2017-18270In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwan...
CVE-2017-18269An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Li...
CVE-2017-9637Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity...
CVE-2017-9635Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are c...
CVE-2017-15855In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kern...
CVE-2017-18268MEDIUM5.9Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote...
CVE-2017-15533Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the R...
CVE-2017-17689The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to pla...
CVE-2017-17688The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to pla...
CVE-2017-2613MEDIUM5.4jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record w...
CVE-2017-2610MEDIUM5.4jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to impr...
CVE-2017-2604MEDIUM4.3In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not ...
CVE-2017-2603LOW2.6Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This coul...
CVE-2017-2602LOW3.1jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the age...
CVE-2017-2612MEDIUM5.4In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392...
CVE-2017-2608HIGH8.8Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserializatio...
CVE-2017-2600MEDIUM4.3In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. The...
CVE-2017-2815HIGH8.1An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafte...
CVE-2017-14439HIGH7.5Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now