2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-16999Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-16998Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-17867Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying th...
CVE-2017-1727IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an a...
CVE-2017-1699IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker c...
CVE-2017-1673IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2017-1672IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker t...
CVE-2017-1669IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to info...
CVE-2017-1665IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow a...
CVE-2017-1664IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow a...
CVE-2017-14960xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL I...
CVE-2017-17837MEDIUM6.1The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the window...
CVE-2017-15714The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code in...
CVE-2017-5754MEDIUM5.6Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl...
CVE-2017-5753MEDIUM5.6Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of ...
CVE-2017-5715MEDIUM5.6Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl...
CVE-2017-8046CRITICAL9.8Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri...
CVE-2017-18020On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary ...
CVE-2017-14383In Dell EMC VNX2 versions prior to Operating Environment for File 8.1.9.217 and VNX1 versions prior to Operating Environ...
CVE-2017-18019In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the ...
CVE-2017-18018HIGH7.1In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symli...
CVE-2017-1000487CRITICAL9.8Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of doub...
CVE-2017-1000486CRITICAL9.8Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
CVE-2017-1000485Nylas Mail Lives 2.2.2 uses 0755 permissions for $HOME/.nylas-mail, which allows local users to obtain sensitive authent...
CVE-2017-1000484By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now