2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-18890MEDIUM4.3An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button th...
CVE-2017-18889MEDIUM4.3An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-mes...
CVE-2017-18888CRITICAL9.8An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching...
CVE-2017-18887MEDIUM5.3An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail addr...
CVE-2017-18886HIGH8.8An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use o...
CVE-2017-18885CRITICAL9.8An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by a...
CVE-2017-18884HIGH8.1An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by u...
CVE-2017-18883CRITICAL9.1An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provid...
CVE-2017-18882MEDIUM6.1An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.
CVE-2017-18881MEDIUM6.1An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location respons...
CVE-2017-18880MEDIUM6.1An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of...
CVE-2017-18879MEDIUM6.1An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field o...
CVE-2017-18878MEDIUM4.3An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking a...
CVE-2017-18874MEDIUM6.5An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A Syst...
CVE-2017-18873MEDIUM5.3An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of se...
CVE-2017-18872MEDIUM4.3An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some ca...
CVE-2017-18877MEDIUM6.1An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2....
CVE-2017-18876MEDIUM4.9An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A Syst...
CVE-2017-18875MEDIUM4.9An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A Syst...
CVE-2017-18871HIGH7.5An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denia...
CVE-2017-18870MEDIUM4.3An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the...
CVE-2017-9104CRITICAL9.8An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
CVE-2017-9103CRITICAL9.8An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Witho...
CVE-2017-9109CRITICAL9.8An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the...
CVE-2017-9108HIGH7.5An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong t...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now