2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-15366Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a sing...
CVE-2017-5996HIGH7.8The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijac...
CVE-2017-15922In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extr...
CVE-2017-15919The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection,...
CVE-2017-3771System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped fro...
CVE-2017-15917In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request a...
CVE-2017-15911The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution...
CVE-2017-15096A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in gluste...
CVE-2017-12160HIGH7.2It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the ...
CVE-2017-12159It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use ...
CVE-2017-12158It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource loca...
CVE-2017-15908HIGH7.5In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an...
CVE-2017-7732A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3...
CVE-2017-7341An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, a...
CVE-2017-7335A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0...
CVE-2017-15907SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via...
CVE-2017-15882The London Trust Media Private Internet Access (PIA) application before 1.3.3.1 for Android allows remote attackers to c...
CVE-2017-15909D-Link DGS-1500 Ax devices before 2.51B021 have a hardcoded password, which allows remote attackers to obtain shell acce...
CVE-2017-15906MEDIUM5.3The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly ...
CVE-2017-1363IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr...
CVE-2017-1295IBM RSA DM contains unspecified vulnerability in CLM Applications with potential for information leakage. IBM X-Force ID...
CVE-2017-1241An unspecified vulnerability in IBM Jazz Foundation based applications might allow the display of stack trace informatio...
CVE-2017-1169IBM DOORS next Generation (DNG/RRC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2017-1164IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript...
CVE-2017-12705A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now