2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1000119 | — | — | 61.3% | Oct 5, 2017 | October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise ... |
| CVE-2017-1000118 | — | — | 1.1% | Oct 5, 2017 | Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service |
| CVE-2017-1000117 | — | — | 77.8% | Oct 5, 2017 | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca... |
| CVE-2017-1000116 | — | — | 5.7% | Oct 5, 2017 | Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks. |
| CVE-2017-1000115 | — | — | 3.8% | Oct 5, 2017 | Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files ... |
| CVE-2017-1000114 | — | — | 1.0% | Oct 5, 2017 | The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API ke... |
| CVE-2017-1000113 | — | — | 0.4% | Oct 5, 2017 | The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkin... |
| CVE-2017-1000112 | HIGH | 7 | 20.8% | Oct 5, 2017 | Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE ... |
| CVE-2017-1000111 | HIGH | 7.8 | 0.4% | Oct 5, 2017 | Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655... |
| CVE-2017-1000110 | — | — | 0.7% | Oct 5, 2017 | Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for reposito... |
| CVE-2017-1000109 | — | — | 0.9% | Oct 5, 2017 | The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persis... |
| CVE-2017-1000108 | — | — | 1.1% | Oct 5, 2017 | The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step t... |
| CVE-2017-1000107 | — | — | 1.2% | Oct 5, 2017 | Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, s... |
| CVE-2017-1000106 | — | — | 0.8% | Oct 5, 2017 | Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for reposito... |
| CVE-2017-1000105 | — | — | 0.9% | Oct 5, 2017 | The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this pe... |
| CVE-2017-1000104 | — | — | 0.8% | Oct 5, 2017 | The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as pass... |
| CVE-2017-1000103 | — | — | 0.7% | Oct 5, 2017 | The custom Details view of the Static Analysis Utilities based DRY Plugin, was vulnerable to a persisted cross-site scri... |
| CVE-2017-1000102 | — | — | 0.7% | Oct 5, 2017 | The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vul... |
| CVE-2017-1000101 | MEDIUM | 6.5 | 3.9% | Oct 5, 2017 | curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers... |
| CVE-2017-1000100 | MEDIUM | 6.5 | 4.0% | Oct 5, 2017 | When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 by... |
| CVE-2017-1000099 | — | — | 3.1% | Oct 5, 2017 | When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTT... |
| CVE-2017-1000098 | HIGH | 7.5 | 2.1% | Oct 5, 2017 | The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size su... |
| CVE-2017-1000097 | HIGH | 7.5 | 1.3% | Oct 5, 2017 | On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in... |
| CVE-2017-1000096 | — | — | 1.6% | Oct 5, 2017 | Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instanc... |
| CVE-2017-1000095 | — | — | 0.8% | Oct 5, 2017 | The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); Default... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now