2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-0371 | HIGH | 7.5 | 1.5% | Feb 18, 2022 | MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to disco... |
| CVE-2017-2488 | HIGH | 7.5 | 0.6% | Dec 23, 2021 | A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implement... |
| CVE-2017-2375 | LOW | 3.3 | 0.2% | Dec 23, 2021 | An issue existed in preventing the uploading of CallKit call history to iCloud. This issue was addressed through improve... |
| CVE-2017-13910 | MEDIUM | 5.5 | 0.2% | Dec 23, 2021 | An access issue was addressed with additional sandbox restrictions on applications. This issue is fixed in macOS High Si... |
| CVE-2017-13909 | MEDIUM | 5.5 | 0.2% | Dec 23, 2021 | An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This is... |
| CVE-2017-13908 | HIGH | 7.8 | 0.2% | Dec 23, 2021 | An issue in handling file permissions was addressed with improved validation. This issue is fixed in macOS High Sierra 1... |
| CVE-2017-13907 | MEDIUM | 6.8 | 0.2% | Dec 23, 2021 | A state management issue was addressed with improved state validation. This issue is fixed in macOS High Sierra 10.13.1,... |
| CVE-2017-13906 | HIGH | 7.8 | 0.6% | Dec 23, 2021 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13.1,... |
| CVE-2017-13905 | HIGH | 8.1 | 0.9% | Dec 23, 2021 | A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra... |
| CVE-2017-13892 | HIGH | 7.5 | 0.9% | Dec 23, 2021 | An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information... |
| CVE-2017-13880 | HIGH | 7.8 | 0.9% | Dec 23, 2021 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An ... |
| CVE-2017-13835 | HIGH | 7.8 | 0.8% | Dec 23, 2021 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13. A... |
| CVE-2017-11071 | — | — | — | Dec 20, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2017-11020 | — | — | — | Dec 20, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2017-20008 | MEDIUM | 6.1 | 0.9% | Nov 29, 2021 | The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in th... |
| CVE-2017-8249 | — | — | — | Nov 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2017-8232 | — | — | — | Nov 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2017-14874 | — | — | — | Nov 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2017-5123 | HIGH | 8.8 | 3.7% | Nov 2, 2021 | Insufficient data validation in waitid allowed an user to escape sandboxes on Linux. |
| CVE-2017-20007 | MEDIUM | 5.3 | 1.1% | Oct 25, 2021 | Ingeteam INGEPAC DA AU AUC_1.13.0.28 (and before) web application allows access to a certain path that contains sensitiv... |
| CVE-2017-16632 | HIGH | 7.5 | 0.7% | Aug 11, 2021 | In SapphireIMS 4097_1, the password in the database is stored in Base64 format. |
| CVE-2017-16631 | MEDIUM | 6.5 | 0.6% | Aug 11, 2021 | In SapphireIMS 4097_1, a guest user is able to change the password of an administrative user by utilizing an Insecure Di... |
| CVE-2017-16630 | HIGH | 8.8 | 0.9% | Aug 11, 2021 | In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installe... |
| CVE-2017-16629 | HIGH | 7.5 | 1.2% | Aug 11, 2021 | In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives ... |
| CVE-2017-18113 | HIGH | 8.8 | 1.8% | Aug 2, 2021 | The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attacker... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now