2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1114 | MEDIUM | 5.4 | 0.7% | Sep 7, 2018 | IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2017-7528 | MEDIUM | 5.2 | 0.6% | Aug 22, 2018 | Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that ... |
| CVE-2017-2662 | MEDIUM | 4.3 | 0.9% | Aug 22, 2018 | A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a rep... |
| CVE-2017-7513 | MEDIUM | 5.4 | 0.5% | Aug 22, 2018 | It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 serv... |
| CVE-2017-1753 | MEDIUM | 5.4 | 0.8% | Aug 20, 2018 | Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, whi... |
| CVE-2017-1732 | MEDIUM | 4.3 | 1.3% | Aug 17, 2018 | IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization token... |
| CVE-2017-15138 | MEDIUM | 5 | 0.9% | Aug 13, 2018 | The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges... |
| CVE-2017-1749 | MEDIUM | 5.3 | 2.4% | Aug 13, 2018 | IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthe... |
| CVE-2017-1755 | MEDIUM | 6.5 | 0.4% | Aug 6, 2018 | IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 could allow a local attacker to inject commands i... |
| CVE-2017-1412 | MEDIUM | 4.3 | 1.0% | Aug 6, 2018 | IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitiv... |
| CVE-2017-1411 | MEDIUM | 5.9 | 1.5% | Aug 6, 2018 | IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong pa... |
| CVE-2017-1409 | MEDIUM | 5.3 | 1.3% | Aug 6, 2018 | IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized u... |
| CVE-2017-1396 | MEDIUM | 4.2 | 0.8% | Aug 6, 2018 | IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical res... |
| CVE-2017-1368 | MEDIUM | 4.3 | 1.3% | Aug 6, 2018 | IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorizatio... |
| CVE-2017-1366 | MEDIUM | 5.9 | 1.0% | Aug 6, 2018 | IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithm... |
| CVE-2017-7518 | MEDIUM | 5.5 | 0.7% | Jul 30, 2018 | A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EF... |
| CVE-2017-7514 | MEDIUM | 4.3 | 0.6% | Jul 30, 2018 | A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before vers... |
| CVE-2017-2648 | MEDIUM | 6.8 | 1.4% | Jul 27, 2018 | It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling ... |
| CVE-2017-15097 | MEDIUM | 6.5 | 0.5% | Jul 27, 2018 | Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to th... |
| CVE-2017-2633 | MEDIUM | 5.4 | 3.0% | Jul 27, 2018 | An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This fla... |
| CVE-2017-2632 | MEDIUM | 4.9 | 1.5% | Jul 27, 2018 | A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create ... |
| CVE-2017-2629 | MEDIUM | 4.3 | 1.4% | Jul 27, 2018 | curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the ... |
| CVE-2017-2626 | MEDIUM | 5.2 | 0.5% | Jul 27, 2018 | It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially us... |
| CVE-2017-2620 | MEDIUM | 5.5 | 3.5% | Jul 27, 2018 | Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds ... |
| CVE-2017-2618 | MEDIUM | 5.5 | 0.5% | Jul 27, 2018 | A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now