2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-9663 | — | — | 1.1% | Jan 9, 2018 | An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS ... |
| CVE-2017-16740 | — | — | 7.1% | Jan 9, 2018 | A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C ... |
| CVE-2017-15131 | — | — | 0.3% | Jan 9, 2018 | It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xd... |
| CVE-2017-15124 | — | — | 2.8% | Jan 9, 2018 | VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory al... |
| CVE-2017-12697 | — | — | 1.4% | Jan 9, 2018 | A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful... |
| CVE-2017-12695 | — | — | 1.9% | Jan 9, 2018 | An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Suc... |
| CVE-2017-1000429 | — | — | 0.8% | Jan 9, 2018 | rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php. |
| CVE-2017-1671 | — | — | 2.7% | Jan 9, 2018 | IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system. ... |
| CVE-2017-1670 | — | — | 1.9% | Jan 9, 2018 | IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send speciall... |
| CVE-2017-1668 | — | — | 1.0% | Jan 9, 2018 | IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an o... |
| CVE-2017-1666 | — | — | 1.7% | Jan 9, 2018 | IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when pr... |
| CVE-2017-1612 | — | — | 0.4% | Jan 9, 2018 | IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' us... |
| CVE-2017-1493 | — | — | 0.7% | Jan 9, 2018 | IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have acces... |
| CVE-2017-1000415 | — | — | 0.5% | Jan 9, 2018 | MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resul... |
| CVE-2017-15129 | MEDIUM | 4.7 | 0.4% | Jan 9, 2018 | A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The funct... |
| CVE-2017-18025 | CRITICAL | 9.8 | 3.3% | Jan 9, 2018 | cgi-bin/drknow.cgi in Innotube ITGuard-Manager 0.0.0.1 allows remote attackers to execute arbitrary OS commands via shel... |
| CVE-2017-7998 | — | — | 2.0% | Jan 8, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary w... |
| CVE-2017-7997 | — | — | 19.3% | Jan 8, 2018 | Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands ... |
| CVE-2017-15883 | — | — | 1.9% | Jan 8, 2018 | Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and conseque... |
| CVE-2017-5971 | — | — | 1.7% | Jan 8, 2018 | SQL injection vulnerability in NewsBee CMS allow remote attackers to execute arbitrary SQL commands. |
| CVE-2017-15913 | — | — | 1.0% | Jan 8, 2018 | The Installer in Whale allows DLL hijacking. |
| CVE-2017-18022 | — | — | 2.7% | Jan 5, 2018 | In ImageMagick 7.0.7-12 Q16, there are memory leaks in MontageImageCommand in MagickWand/montage.c. |
| CVE-2017-18021 | — | — | 2.4% | Jan 5, 2018 | It was discovered that QtPass before 1.2.1, when using the built-in password generator, generates possibly predictable a... |
| CVE-2017-15550 | — | — | 8.2% | Jan 5, 2018 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.... |
| CVE-2017-15549 | — | — | 5.5% | Jan 5, 2018 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now