2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-7326Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit mem...
CVE-2017-7325Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.
CVE-2017-18044A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain mess...
CVE-2017-15713Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows ...
CVE-2017-6142X509 certificate verification was not correctly implemented in the early access "user id" feature in the F5 BIG-IP Advan...
CVE-2017-1693IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users se...
CVE-2017-17860In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It ...
CVE-2017-12197It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user w...
CVE-2017-3158A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of bloc...
CVE-2017-5170An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior ver...
CVE-2017-12729A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elem...
CVE-2017-16863The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScrip...
CVE-2017-17839Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-17838Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-15523Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-15522Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-15521Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-15520Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-18033The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abor...
CVE-2017-15869Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inj...
CVE-2017-12308MEDIUM6.1A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, r...
CVE-2017-12307MEDIUM6.1A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, r...
CVE-2017-5699Input validation error in Intel MinnowBoard 3 Firmware versions prior to 0.65 allow local attacker to cause denial of se...
CVE-2017-10301Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: E...
CVE-2017-10282Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2 a...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now