2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17463 | — | — | 1.3% | Dec 8, 2017 | Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, ... |
| CVE-2017-17461 | — | — | — | Dec 8, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-14386 | — | — | 0.6% | Dec 7, 2017 | The web user interface of Dell 2335dn and 2355dn Multifunction Laser Printers, firmware versions prior to V2.70.06.26 A1... |
| CVE-2017-1000410 | — | — | 4.3% | Dec 7, 2017 | The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP comma... |
| CVE-2017-17459 | — | — | 2.8% | Dec 7, 2017 | http_transport.c in Fossil before 2.4, when the SSH sync protocol is used, allows user-assisted remote attackers to exec... |
| CVE-2017-17458 | — | — | 6.3% | Dec 7, 2017 | In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arb... |
| CVE-2017-11937 | — | — | 28.4% | Dec 7, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows ... |
| CVE-2017-3738 | MEDIUM | 5.9 | 13.4% | Dec 7, 2017 | There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No... |
| CVE-2017-3737 | — | — | 78.7% | Dec 7, 2017 | OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error... |
| CVE-2017-1498 | — | — | 0.7% | Dec 7, 2017 | IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript... |
| CVE-2017-1497 | — | — | 1.0% | Dec 7, 2017 | IBM Sterling File Gateway 2.2 could allow an unauthorized user to view files they should not have access to providing th... |
| CVE-2017-1487 | — | — | 1.1% | Dec 7, 2017 | IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on... |
| CVE-2017-1482 | — | — | 0.7% | Dec 7, 2017 | IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users ... |
| CVE-2017-1481 | — | — | 0.9% | Dec 7, 2017 | IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another use... |
| CVE-2017-1465 | — | — | 0.6% | Dec 7, 2017 | IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuad... |
| CVE-2017-1433 | — | — | 1.4% | Dec 7, 2017 | IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow an authenticated user to insert messages with a corrupt RFH header into t... |
| CVE-2017-1356 | — | — | 1.4% | Dec 7, 2017 | IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-cra... |
| CVE-2017-1355 | — | — | 1.0% | Dec 7, 2017 | IBM Atlas eDiscovery Process Management 6.0.3 stores sensitive information in URL parameters. This may lead to informati... |
| CVE-2017-1354 | — | — | 0.5% | Dec 7, 2017 | IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2017-1353 | — | — | 0.7% | Dec 7, 2017 | IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when... |
| CVE-2017-1342 | — | — | 0.7% | Dec 7, 2017 | IBM Insights Foundation for Energy 2.0 could reveal sensitive information in error messages to authenticated users that ... |
| CVE-2017-1341 | — | — | 1.0% | Dec 7, 2017 | IBM WebSphere MQ 8.0 and 9.0 could allow, under special circumstances, an unauthorized user to access an object which th... |
| CVE-2017-1336 | — | — | 0.7% | Dec 7, 2017 | IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and f... |
| CVE-2017-1271 | — | — | 0.8% | Dec 7, 2017 | IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiat... |
| CVE-2017-17457 | — | — | — | Dec 7, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-14246. Reason: This candidate is a duplicate of ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now