2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1000395Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally availab...
CVE-2017-1000394Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-serv...
CVE-2017-1000393Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could config...
CVE-2017-1000392Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a...
CVE-2017-1000391Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual u...
CVE-2017-1000390Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone w...
CVE-2017-1000389Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained ...
CVE-2017-1000388Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modi...
CVE-2017-1000387Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson...
CVE-2017-1000386Jenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary...
CVE-2017-3762Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon cre...
CVE-2017-15703Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained ma...
CVE-2017-15132A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dove...
CVE-2017-1000505In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts...
CVE-2017-15365sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-2...
CVE-2017-1000414ImpulseAdventure JPEGsnoop version 1.7.5 is vulnerable to a division by zero in the JFIF decode handling resulting denia...
CVE-2017-4962Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-1000468Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2017-1000464Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2017-15546The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulne...
CVE-2017-1000504A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of executio...
CVE-2017-1000503A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of executi...
CVE-2017-1000502Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbi...
CVE-2017-1000474Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/veh...
CVE-2017-15135It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison o...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now