2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16999 | — | — | — | Jan 4, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2017-16998 | — | — | — | Jan 4, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2017-17867 | — | — | 11.1% | Jan 4, 2018 | Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying th... |
| CVE-2017-1727 | — | — | 0.9% | Jan 4, 2018 | IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an a... |
| CVE-2017-1699 | — | — | 0.3% | Jan 4, 2018 | IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker c... |
| CVE-2017-1673 | — | — | 0.9% | Jan 4, 2018 | IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2017-1672 | — | — | 0.6% | Jan 4, 2018 | IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker t... |
| CVE-2017-1669 | — | — | 1.1% | Jan 4, 2018 | IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to info... |
| CVE-2017-1665 | — | — | 0.8% | Jan 4, 2018 | IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow a... |
| CVE-2017-1664 | — | — | 0.8% | Jan 4, 2018 | IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow a... |
| CVE-2017-14960 | — | — | 3.7% | Jan 4, 2018 | xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL I... |
| CVE-2017-17837 | MEDIUM | 6.1 | 4.5% | Jan 4, 2018 | The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the window... |
| CVE-2017-15714 | — | — | 3.3% | Jan 4, 2018 | The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code in... |
| CVE-2017-5754 | MEDIUM | 5.6 | 84.2% | Jan 4, 2018 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl... |
| CVE-2017-5753 | MEDIUM | 5.6 | 93.8% | Jan 4, 2018 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of ... |
| CVE-2017-5715 | MEDIUM | 5.6 | 74.0% | Jan 4, 2018 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl... |
| CVE-2017-8046 | CRITICAL | 9.8 | 72.8% | Jan 4, 2018 | Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri... |
| CVE-2017-18020 | — | — | 0.4% | Jan 4, 2018 | On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary ... |
| CVE-2017-14383 | — | — | 0.8% | Jan 4, 2018 | In Dell EMC VNX2 versions prior to Operating Environment for File 8.1.9.217 and VNX1 versions prior to Operating Environ... |
| CVE-2017-18019 | — | — | 1.2% | Jan 4, 2018 | In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the ... |
| CVE-2017-18018 | HIGH | 7.1 | 0.3% | Jan 4, 2018 | In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symli... |
| CVE-2017-1000487 | CRITICAL | 9.8 | 6.5% | Jan 3, 2018 | Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of doub... |
| CVE-2017-1000486 | CRITICAL | 9.8 | 94.1% | Jan 3, 2018 | Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution |
| CVE-2017-1000485 | — | — | 0.3% | Jan 3, 2018 | Nylas Mail Lives 2.2.2 uses 0755 permissions for $HOME/.nylas-mail, which allows local users to obtain sensitive authent... |
| CVE-2017-1000484 | — | — | 0.7% | Jan 3, 2018 | By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now