2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-15366 | — | — | 1.4% | Oct 26, 2017 | Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a sing... |
| CVE-2017-5996 | HIGH | 7.8 | 1.3% | Oct 26, 2017 | The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijac... |
| CVE-2017-15922 | — | — | 1.3% | Oct 26, 2017 | In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extr... |
| CVE-2017-15919 | — | — | 2.5% | Oct 26, 2017 | The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection,... |
| CVE-2017-3771 | — | — | 0.8% | Oct 26, 2017 | System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped fro... |
| CVE-2017-15917 | — | — | 0.7% | Oct 26, 2017 | In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request a... |
| CVE-2017-15911 | — | — | 0.7% | Oct 26, 2017 | The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution... |
| CVE-2017-15096 | — | — | 0.3% | Oct 26, 2017 | A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in gluste... |
| CVE-2017-12160 | HIGH | 7.2 | 1.9% | Oct 26, 2017 | It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the ... |
| CVE-2017-12159 | — | — | 2.4% | Oct 26, 2017 | It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use ... |
| CVE-2017-12158 | — | — | 1.0% | Oct 26, 2017 | It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource loca... |
| CVE-2017-15908 | HIGH | 7.5 | 23.6% | Oct 26, 2017 | In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an... |
| CVE-2017-7732 | — | — | 2.1% | Oct 26, 2017 | A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3... |
| CVE-2017-7341 | — | — | 3.9% | Oct 26, 2017 | An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, a... |
| CVE-2017-7335 | — | — | 0.5% | Oct 26, 2017 | A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0... |
| CVE-2017-15907 | — | — | 1.3% | Oct 26, 2017 | SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via... |
| CVE-2017-15882 | — | — | 1.8% | Oct 26, 2017 | The London Trust Media Private Internet Access (PIA) application before 1.3.3.1 for Android allows remote attackers to c... |
| CVE-2017-15909 | — | — | 1.7% | Oct 26, 2017 | D-Link DGS-1500 Ax devices before 2.51B021 have a hardcoded password, which allows remote attackers to obtain shell acce... |
| CVE-2017-15906 | MEDIUM | 5.3 | 3.4% | Oct 26, 2017 | The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly ... |
| CVE-2017-1363 | — | — | 0.7% | Oct 25, 2017 | IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr... |
| CVE-2017-1295 | — | — | 0.9% | Oct 25, 2017 | IBM RSA DM contains unspecified vulnerability in CLM Applications with potential for information leakage. IBM X-Force ID... |
| CVE-2017-1241 | — | — | 0.9% | Oct 25, 2017 | An unspecified vulnerability in IBM Jazz Foundation based applications might allow the display of stack trace informatio... |
| CVE-2017-1169 | — | — | 0.7% | Oct 25, 2017 | IBM DOORS next Generation (DNG/RRC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2017-1164 | — | — | 0.7% | Oct 25, 2017 | IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript... |
| CVE-2017-12705 | — | — | 0.4% | Oct 25, 2017 | A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now