2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-0371HIGH7.5MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to disco...
CVE-2017-2488HIGH7.5A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implement...
CVE-2017-2375LOW3.3An issue existed in preventing the uploading of CallKit call history to iCloud. This issue was addressed through improve...
CVE-2017-13910MEDIUM5.5An access issue was addressed with additional sandbox restrictions on applications. This issue is fixed in macOS High Si...
CVE-2017-13909MEDIUM5.5An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This is...
CVE-2017-13908HIGH7.8An issue in handling file permissions was addressed with improved validation. This issue is fixed in macOS High Sierra 1...
CVE-2017-13907MEDIUM6.8A state management issue was addressed with improved state validation. This issue is fixed in macOS High Sierra 10.13.1,...
CVE-2017-13906HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13.1,...
CVE-2017-13905HIGH8.1A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra...
CVE-2017-13892HIGH7.5An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information...
CVE-2017-13880HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An ...
CVE-2017-13835HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13. A...
CVE-2017-11071Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2017-11020Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2017-20008MEDIUM6.1The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in th...
CVE-2017-8249Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2017-8232Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2017-14874Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2017-5123HIGH8.8Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
CVE-2017-20007MEDIUM5.3Ingeteam INGEPAC DA AU AUC_1.13.0.28 (and before) web application allows access to a certain path that contains sensitiv...
CVE-2017-16632HIGH7.5In SapphireIMS 4097_1, the password in the database is stored in Base64 format.
CVE-2017-16631MEDIUM6.5In SapphireIMS 4097_1, a guest user is able to change the password of an administrative user by utilizing an Insecure Di...
CVE-2017-16630HIGH8.8In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installe...
CVE-2017-16629HIGH7.5In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives ...
CVE-2017-18113HIGH8.8The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attacker...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now