2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7326 | — | — | 0.8% | Jan 19, 2018 | Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit mem... |
| CVE-2017-7325 | — | — | 1.1% | Jan 19, 2018 | Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open. |
| CVE-2017-18044 | — | — | 69.8% | Jan 19, 2018 | A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain mess... |
| CVE-2017-15713 | — | — | 2.3% | Jan 19, 2018 | Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows ... |
| CVE-2017-6142 | — | — | 0.4% | Jan 19, 2018 | X509 certificate verification was not correctly implemented in the early access "user id" feature in the F5 BIG-IP Advan... |
| CVE-2017-1693 | — | — | 1.0% | Jan 19, 2018 | IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users se... |
| CVE-2017-17860 | — | — | 0.3% | Jan 18, 2018 | In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It ... |
| CVE-2017-12197 | — | — | 1.5% | Jan 18, 2018 | It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user w... |
| CVE-2017-3158 | — | — | 1.2% | Jan 18, 2018 | A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of bloc... |
| CVE-2017-5170 | — | — | 1.5% | Jan 18, 2018 | An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior ver... |
| CVE-2017-12729 | — | — | 1.2% | Jan 18, 2018 | A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elem... |
| CVE-2017-16863 | — | — | 0.8% | Jan 18, 2018 | The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScrip... |
| CVE-2017-17839 | — | — | — | Jan 18, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2017-17838 | — | — | — | Jan 18, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2017-15523 | — | — | — | Jan 18, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2017-15522 | — | — | — | Jan 18, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2017-15521 | — | — | — | Jan 18, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2017-15520 | — | — | — | Jan 18, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2017-18033 | — | — | 0.6% | Jan 18, 2018 | The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abor... |
| CVE-2017-15869 | — | — | 1.4% | Jan 18, 2018 | Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inj... |
| CVE-2017-12308 | MEDIUM | 6.1 | 0.8% | Jan 18, 2018 | A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, r... |
| CVE-2017-12307 | MEDIUM | 6.1 | 0.9% | Jan 18, 2018 | A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, r... |
| CVE-2017-5699 | — | — | 0.3% | Jan 18, 2018 | Input validation error in Intel MinnowBoard 3 Firmware versions prior to 0.65 allow local attacker to cause denial of se... |
| CVE-2017-10301 | — | — | 1.5% | Jan 18, 2018 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: E... |
| CVE-2017-10282 | — | — | 1.8% | Jan 18, 2018 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2 a... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now