2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1290IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2017-1148IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain se...
CVE-2017-1147IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2017-1000122The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate certain message metadata,...
CVE-2017-1000121CRITICAL9.8The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, al...
CVE-2017-16359In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf....
CVE-2017-16358In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string...
CVE-2017-16357In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_ve...
CVE-2017-15918Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial...
CVE-2017-15566Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x b...
CVE-2017-14992Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17....
CVE-2017-1001001PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which c...
CVE-2017-16353GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function...
CVE-2017-16352GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image dir...
CVE-2017-12625Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking pol...
CVE-2017-1000245The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and pas...
CVE-2017-1000244Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification
CVE-2017-1000243Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any u...
CVE-2017-1000242Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information di...
CVE-2017-14027A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a...
CVE-2017-14021A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G versio...
CVE-2017-16248The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there i...
CVE-2017-16244Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for po...
CVE-2017-15535MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompr...
CVE-2017-14376EMC AppSync Server prior to 3.5.0.1 contains database accounts with hardcoded passwords that could potentially be exploi...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now