2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1000119October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise ...
CVE-2017-1000118Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service
CVE-2017-1000117A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca...
CVE-2017-1000116Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
CVE-2017-1000115Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files ...
CVE-2017-1000114The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API ke...
CVE-2017-1000113The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkin...
CVE-2017-1000112HIGH7Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE ...
CVE-2017-1000111HIGH7.8Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655...
CVE-2017-1000110Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for reposito...
CVE-2017-1000109The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persis...
CVE-2017-1000108The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step t...
CVE-2017-1000107Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, s...
CVE-2017-1000106Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for reposito...
CVE-2017-1000105The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this pe...
CVE-2017-1000104The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as pass...
CVE-2017-1000103The custom Details view of the Static Analysis Utilities based DRY Plugin, was vulnerable to a persisted cross-site scri...
CVE-2017-1000102The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vul...
CVE-2017-1000101MEDIUM6.5curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers...
CVE-2017-1000100MEDIUM6.5When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 by...
CVE-2017-1000099When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTT...
CVE-2017-1000098HIGH7.5The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size su...
CVE-2017-1000097HIGH7.5On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in...
CVE-2017-1000096Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instanc...
CVE-2017-1000095The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); Default...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now