2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1290 | — | — | 0.7% | Nov 1, 2017 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to e... |
| CVE-2017-1148 | — | — | 1.3% | Nov 1, 2017 | IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain se... |
| CVE-2017-1147 | — | — | 0.7% | Nov 1, 2017 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to e... |
| CVE-2017-1000122 | — | — | 1.1% | Nov 1, 2017 | The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate certain message metadata,... |
| CVE-2017-1000121 | CRITICAL | 9.8 | 1.2% | Nov 1, 2017 | The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, al... |
| CVE-2017-16359 | — | — | 1.2% | Nov 1, 2017 | In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.... |
| CVE-2017-16358 | — | — | 1.0% | Nov 1, 2017 | In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string... |
| CVE-2017-16357 | — | — | 1.0% | Nov 1, 2017 | In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_ve... |
| CVE-2017-15918 | — | — | 1.2% | Nov 1, 2017 | Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial... |
| CVE-2017-15566 | — | — | 0.6% | Nov 1, 2017 | Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x b... |
| CVE-2017-14992 | — | — | 2.5% | Nov 1, 2017 | Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.... |
| CVE-2017-1001001 | — | — | 0.6% | Nov 1, 2017 | PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which c... |
| CVE-2017-16353 | — | — | 13.7% | Nov 1, 2017 | GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function... |
| CVE-2017-16352 | — | — | 14.5% | Nov 1, 2017 | GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image dir... |
| CVE-2017-12625 | — | — | 1.4% | Nov 1, 2017 | Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking pol... |
| CVE-2017-1000245 | — | — | 1.4% | Nov 1, 2017 | The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and pas... |
| CVE-2017-1000244 | — | — | 0.8% | Nov 1, 2017 | Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification |
| CVE-2017-1000243 | — | — | 0.6% | Nov 1, 2017 | Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any u... |
| CVE-2017-1000242 | — | — | 0.4% | Nov 1, 2017 | Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information di... |
| CVE-2017-14027 | — | — | 2.8% | Nov 1, 2017 | A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a... |
| CVE-2017-14021 | — | — | 1.9% | Nov 1, 2017 | A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G versio... |
| CVE-2017-16248 | — | — | 2.4% | Nov 1, 2017 | The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there i... |
| CVE-2017-16244 | — | — | 2.0% | Nov 1, 2017 | Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for po... |
| CVE-2017-15535 | — | — | 1.6% | Nov 1, 2017 | MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompr... |
| CVE-2017-14376 | — | — | 0.3% | Nov 1, 2017 | EMC AppSync Server prior to 3.5.0.1 contains database accounts with hardcoded passwords that could potentially be exploi... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now