2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-6932Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is us...
CVE-2017-6931In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update ...
CVE-2017-6930In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks th...
CVE-2017-6929A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerabilit...
CVE-2017-6928Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has ...
CVE-2017-6927Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function whi...
CVE-2017-6926In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comme...
CVE-2017-18212An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex fu...
CVE-2017-15134A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x bef...
CVE-2017-18211In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/o...
CVE-2017-18210In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function BenchmarkOpenCLDevices in Magic...
CVE-2017-18209In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulner...
CVE-2017-9286HIGH7.8The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts runnin...
CVE-2017-9274HIGH7.8A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager w...
CVE-2017-9271LOW3.3The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to g...
CVE-2017-9270HIGH8.7In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryp...
CVE-2017-9269HIGH7.7In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious reposi...
CVE-2017-9268MEDIUM4.4In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions...
CVE-2017-7436HIGH8.1In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead ...
CVE-2017-7435HIGH8.1In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead ...
CVE-2017-7426MEDIUM5.4The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that coul...
CVE-2017-5188MEDIUM5The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside o...
CVE-2017-14804CRITICAL9.9The build package before 20171128 did not check directory names during extraction of build results that allowed untruste...
CVE-2017-14800MEDIUM5.4A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter o...
CVE-2017-14799MEDIUM4.6A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now