2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6932 | — | — | 1.2% | Mar 1, 2018 | Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is us... |
| CVE-2017-6931 | — | — | 1.1% | Mar 1, 2018 | In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update ... |
| CVE-2017-6930 | — | — | 1.3% | Mar 1, 2018 | In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks th... |
| CVE-2017-6929 | — | — | 1.3% | Mar 1, 2018 | A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerabilit... |
| CVE-2017-6928 | — | — | 1.1% | Mar 1, 2018 | Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has ... |
| CVE-2017-6927 | — | — | 1.7% | Mar 1, 2018 | Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function whi... |
| CVE-2017-6926 | — | — | 1.2% | Mar 1, 2018 | In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comme... |
| CVE-2017-18212 | — | — | 1.9% | Mar 1, 2018 | An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex fu... |
| CVE-2017-15134 | — | — | 4.1% | Mar 1, 2018 | A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x bef... |
| CVE-2017-18211 | — | — | 4.1% | Mar 1, 2018 | In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/o... |
| CVE-2017-18210 | — | — | 2.6% | Mar 1, 2018 | In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function BenchmarkOpenCLDevices in Magic... |
| CVE-2017-18209 | — | — | 3.0% | Mar 1, 2018 | In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulner... |
| CVE-2017-9286 | HIGH | 7.8 | 1.2% | Mar 1, 2018 | The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts runnin... |
| CVE-2017-9274 | HIGH | 7.8 | 2.3% | Mar 1, 2018 | A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager w... |
| CVE-2017-9271 | LOW | 3.3 | 0.3% | Mar 1, 2018 | The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to g... |
| CVE-2017-9270 | HIGH | 8.7 | 2.0% | Mar 1, 2018 | In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryp... |
| CVE-2017-9269 | HIGH | 7.7 | 2.3% | Mar 1, 2018 | In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious reposi... |
| CVE-2017-9268 | MEDIUM | 4.4 | 0.6% | Mar 1, 2018 | In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions... |
| CVE-2017-7436 | HIGH | 8.1 | 1.8% | Mar 1, 2018 | In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead ... |
| CVE-2017-7435 | HIGH | 8.1 | 1.8% | Mar 1, 2018 | In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead ... |
| CVE-2017-7426 | MEDIUM | 5.4 | 1.1% | Mar 1, 2018 | The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that coul... |
| CVE-2017-5188 | MEDIUM | 5 | 1.2% | Mar 1, 2018 | The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside o... |
| CVE-2017-14804 | CRITICAL | 9.9 | 1.7% | Mar 1, 2018 | The build package before 20171128 did not check directory names during extraction of build results that allowed untruste... |
| CVE-2017-14800 | MEDIUM | 5.4 | 0.8% | Mar 1, 2018 | A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter o... |
| CVE-2017-14799 | MEDIUM | 4.6 | 0.8% | Mar 1, 2018 | A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now