2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-15570 | — | — | 1.2% | Oct 18, 2017 | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via ... |
| CVE-2017-15569 | — | — | 0.9% | Oct 18, 2017 | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a m... |
| CVE-2017-15568 | — | — | 0.9% | Oct 18, 2017 | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via... |
| CVE-2017-9625 | — | — | 2.3% | Oct 17, 2017 | An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web applica... |
| CVE-2017-15565 | — | — | 2.1% | Oct 17, 2017 | In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via ... |
| CVE-2017-14013 | — | — | 0.9% | Oct 17, 2017 | A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interf... |
| CVE-2017-14011 | — | — | 0.6% | Oct 17, 2017 | A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application ... |
| CVE-2017-14009 | — | — | 0.7% | Oct 17, 2017 | An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated... |
| CVE-2017-14007 | — | — | 0.9% | Oct 17, 2017 | An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The user's... |
| CVE-2017-14005 | — | — | 1.4% | Oct 17, 2017 | An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a ... |
| CVE-2017-13999 | — | — | 2.8% | Oct 17, 2017 | A Stack-based Buffer Overflow issue was discovered in WECON LEVI Studio HMI Editor v1.8.1 and prior. Multiple stack-base... |
| CVE-2017-15539 | — | — | 1.2% | Oct 17, 2017 | SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php. |
| CVE-2017-6273 | — | — | 0.3% | Oct 17, 2017 | NVIDIA ADSP Firmware contains a vulnerability in the ADSP Loader component where there is the potential to write to a me... |
| CVE-2017-5531 | HIGH | 8 | 1.3% | Oct 17, 2017 | Deployments of TIBCO Managed File Transfer Command Center versions 8.0.0 and 8.0.1 and TIBCO Managed File Transfer Inter... |
| CVE-2017-3761 | — | — | 4.2% | Oct 17, 2017 | The Lenovo Service Framework Android application executes some system commands without proper sanitization of external i... |
| CVE-2017-3760 | — | — | 0.8% | Oct 17, 2017 | The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verificat... |
| CVE-2017-3759 | — | — | 1.7% | Oct 17, 2017 | The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This ... |
| CVE-2017-3758 | — | — | 2.7% | Oct 17, 2017 | Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to e... |
| CVE-2017-15538 | — | — | 0.9% | Oct 17, 2017 | Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenti... |
| CVE-2017-8805 | — | — | 3.0% | Oct 17, 2017 | Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct dire... |
| CVE-2017-15537 | — | — | 0.4% | Oct 17, 2017 | The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave featu... |
| CVE-2017-13088 | — | — | 1.8% | Oct 17, 2017 | Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IG... |
| CVE-2017-13087 | — | — | 1.7% | Oct 17, 2017 | Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when pr... |
| CVE-2017-13086 | — | — | 2.0% | Oct 17, 2017 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) duri... |
| CVE-2017-13084 | — | — | 2.2% | Oct 17, 2017 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) du... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now