2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-16683Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prev...
CVE-2017-16682SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allow...
CVE-2017-16681Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10,...
CVE-2017-16680Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST e...
CVE-2017-16679URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP...
CVE-2017-16678Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and E...
CVE-2017-17555The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubi...
CVE-2017-17554A NULL pointer dereference (DoS) Vulnerability was found in the function aubio_source_avcodec_readframe in io/source_avc...
CVE-2017-17553The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vu...
CVE-2017-2886HIGH7.8A memory corruption vulnerability exists in the .PSD parsing functionality of ACDSee Ultimate 10.0.0.292. A specially cr...
CVE-2017-8867Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 use AES-128 with ECB mode to encrypt voice t...
CVE-2017-8866Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, ...
CVE-2017-8865Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 do not provide sufficient protections agains...
CVE-2017-1760IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a local user to crash the queue manager agent thread and expose some sens...
CVE-2017-1683IBM Connections Engagement Center 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar...
CVE-2017-1632IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2017-1613IBM Connections 6.0 could allow an unauthenticated remote attacker to gain unauthenticated or unauthorized access to non...
CVE-2017-1606IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. ...
CVE-2017-15897LOW3.1Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill valu...
CVE-2017-15896CRITICAL9.1Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake fai...
CVE-2017-1550IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IBM X-Force ID: 131290...
CVE-2017-1549IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2017-1548IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could sen...
CVE-2017-1536IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This...
CVE-2017-1507IBM Jazz Foundation Products could disclose sensitive information during a scan that could lead to further attacks again...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now