2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1000395 | — | — | 1.3% | Jan 26, 2018 | Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally availab... |
| CVE-2017-1000394 | — | — | 1.2% | Jan 26, 2018 | Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-serv... |
| CVE-2017-1000393 | — | — | 2.6% | Jan 26, 2018 | Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could config... |
| CVE-2017-1000392 | — | — | 1.1% | Jan 26, 2018 | Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a... |
| CVE-2017-1000391 | — | — | 1.5% | Jan 26, 2018 | Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual u... |
| CVE-2017-1000390 | — | — | 0.7% | Jan 26, 2018 | Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone w... |
| CVE-2017-1000389 | — | — | 0.9% | Jan 26, 2018 | Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained ... |
| CVE-2017-1000388 | — | — | 0.6% | Jan 26, 2018 | Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modi... |
| CVE-2017-1000387 | — | — | 0.4% | Jan 26, 2018 | Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson... |
| CVE-2017-1000386 | — | — | 0.8% | Jan 26, 2018 | Jenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary... |
| CVE-2017-3762 | — | — | 0.4% | Jan 26, 2018 | Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon cre... |
| CVE-2017-15703 | — | — | 0.9% | Jan 25, 2018 | Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained ma... |
| CVE-2017-15132 | — | — | 3.2% | Jan 25, 2018 | A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dove... |
| CVE-2017-1000505 | — | — | 1.0% | Jan 25, 2018 | In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts... |
| CVE-2017-15365 | — | — | 3.4% | Jan 25, 2018 | sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-2... |
| CVE-2017-1000414 | — | — | 1.4% | Jan 25, 2018 | ImpulseAdventure JPEGsnoop version 1.7.5 is vulnerable to a division by zero in the JFIF decode handling resulting denia... |
| CVE-2017-4962 | — | — | — | Jan 25, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2017-1000468 | — | — | — | Jan 25, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-1000464 | — | — | — | Jan 25, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-15546 | — | — | 1.2% | Jan 25, 2018 | The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulne... |
| CVE-2017-1000504 | — | — | 1.0% | Jan 24, 2018 | A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of executio... |
| CVE-2017-1000503 | — | — | 1.2% | Jan 24, 2018 | A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of executi... |
| CVE-2017-1000502 | — | — | 1.6% | Jan 24, 2018 | Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbi... |
| CVE-2017-1000474 | — | — | 2.2% | Jan 24, 2018 | Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/veh... |
| CVE-2017-15135 | — | — | 3.9% | Jan 24, 2018 | It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison o... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now