2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-15570In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via ...
CVE-2017-15569In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a m...
CVE-2017-15568In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via...
CVE-2017-9625An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web applica...
CVE-2017-15565In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via ...
CVE-2017-14013A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interf...
CVE-2017-14011A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application ...
CVE-2017-14009An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated...
CVE-2017-14007An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The user's...
CVE-2017-14005An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a ...
CVE-2017-13999A Stack-based Buffer Overflow issue was discovered in WECON LEVI Studio HMI Editor v1.8.1 and prior. Multiple stack-base...
CVE-2017-15539SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.
CVE-2017-6273NVIDIA ADSP Firmware contains a vulnerability in the ADSP Loader component where there is the potential to write to a me...
CVE-2017-5531HIGH8Deployments of TIBCO Managed File Transfer Command Center versions 8.0.0 and 8.0.1 and TIBCO Managed File Transfer Inter...
CVE-2017-3761The Lenovo Service Framework Android application executes some system commands without proper sanitization of external i...
CVE-2017-3760The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verificat...
CVE-2017-3759The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This ...
CVE-2017-3758Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to e...
CVE-2017-15538Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenti...
CVE-2017-8805Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct dire...
CVE-2017-15537The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave featu...
CVE-2017-13088Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IG...
CVE-2017-13087Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when pr...
CVE-2017-13086Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) duri...
CVE-2017-13084Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) du...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now