2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-12163MEDIUM4.1An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14,...
CVE-2017-7562MEDIUM6.5An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of cli...
CVE-2017-7558MEDIUM5.1A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sc...
CVE-2017-7545MEDIUM6.5It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while ...
CVE-2017-7543MEDIUM5.3A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1...
CVE-2017-7539MEDIUM5.3An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection...
CVE-2017-2664MEDIUM6.5CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the ra...
CVE-2017-7537MEDIUM5.9It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pk...
CVE-2017-7535MEDIUM6.1foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting t...
CVE-2017-7526MEDIUM6.1libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 ...
CVE-2017-1633MEDIUM4.3IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name in...
CVE-2017-1575MEDIUM5.1IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected c...
CVE-2017-2673MEDIUM6.8An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An...
CVE-2017-15137MEDIUM4.3The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", fo...
CVE-2017-7468MEDIUM4.8In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client cer...
CVE-2017-2638MEDIUM6.5It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker...
CVE-2017-1395MEDIUM5.9IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to...
CVE-2017-14710MEDIUM5.9The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify...
CVE-2017-1793MEDIUM5.4IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulner...
CVE-2017-1792MEDIUM5.4IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulner...
CVE-2017-1791MEDIUM5.4IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulner...
CVE-2017-1738MEDIUM6.3IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 contains an undisclosed vulnerability that would al...
CVE-2017-1729MEDIUM5.4IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulner...
CVE-2017-1795MEDIUM4.4IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via tra...
CVE-2017-1509MEDIUM4.3IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that c...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now