2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1000433HIGH8.1pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to...
CVE-2017-1000432Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
CVE-2017-1000427marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
CVE-2017-1000425Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allow...
CVE-2017-1000426MEDIUM6.1MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possib...
CVE-2017-1000431eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, ...
CVE-2017-1000430rust-base64 version <= 0.5.1 is vulnerable to a buffer overflow when calculating the size of a buffer to use when encodi...
CVE-2017-1000424Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PD...
CVE-2017-1000423b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic instal...
CVE-2017-1000422Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in mem...
CVE-2017-1000421Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code exec...
CVE-2017-1000420Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
CVE-2017-1000419phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port s...
CVE-2017-1000458Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to c...
CVE-2017-1000457Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject ar...
CVE-2017-1000456freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent c...
CVE-2017-1000418The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to ...
CVE-2017-1557IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that c...
CVE-2017-1000455GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creat...
CVE-2017-1000454CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in loca...
CVE-2017-1000453CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in u...
CVE-2017-1000452An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which coul...
CVE-2017-1000451fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, howev...
CVE-2017-1000450HIGH8.8In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which c...
CVE-2017-1000449Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now