2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1000094 | — | — | 1.0% | Oct 5, 2017 | Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one th... |
| CVE-2017-1000093 | — | — | 0.7% | Oct 5, 2017 | Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request For... |
| CVE-2017-1000092 | — | — | 0.8% | Oct 5, 2017 | Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to ... |
| CVE-2017-1000091 | — | — | 0.6% | Oct 5, 2017 | GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validat... |
| CVE-2017-1000090 | — | — | 0.7% | Oct 5, 2017 | Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself ... |
| CVE-2017-1000089 | — | — | 1.0% | Oct 5, 2017 | Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact wit... |
| CVE-2017-1000088 | — | — | 0.7% | Oct 5, 2017 | The Sidebar Link plugin allows users able to configure jobs, views, and agents to add entries to the sidebar of these ob... |
| CVE-2017-1000087 | — | — | 0.8% | Oct 5, 2017 | GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one the... |
| CVE-2017-1000086 | — | — | 1.1% | Oct 5, 2017 | The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change i... |
| CVE-2017-1000085 | — | — | 1.0% | Oct 5, 2017 | Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list... |
| CVE-2017-1000084 | — | — | 0.8% | Oct 5, 2017 | Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the bu... |
| CVE-2017-1000077 | — | — | — | Oct 5, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d... |
| CVE-2017-1000076 | — | — | — | Oct 5, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d... |
| CVE-2017-12149 | CRITICAL | 9.8 | 90.7% | Oct 4, 2017 | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter ... |
| CVE-2017-9792 | — | — | 1.6% | Oct 4, 2017 | In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any... |
| CVE-2017-8048 | — | — | 1.2% | Oct 4, 2017 | In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to... |
| CVE-2017-8047 | — | — | 0.8% | Oct 4, 2017 | In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in som... |
| CVE-2017-1541 | — | — | 1.5% | Oct 4, 2017 | A flaw in the AIX 5.3, 6.1, 7.1, and 7.2 JRE/SDK installp and updatep packages prevented the java.security, java.policy ... |
| CVE-2017-15011 | — | — | 1.4% | Oct 4, 2017 | The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and all... |
| CVE-2017-15010 | — | — | 3.3% | Oct 4, 2017 | A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An at... |
| CVE-2017-15009 | — | — | 0.7% | Oct 4, 2017 | PRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page),... |
| CVE-2017-15008 | — | — | 0.5% | Oct 4, 2017 | PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to ... |
| CVE-2017-14997 | — | — | 3.4% | Oct 4, 2017 | GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an i... |
| CVE-2017-14995 | — | — | 0.6% | Oct 4, 2017 | The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server ... |
| CVE-2017-14994 | — | — | 2.9% | Oct 4, 2017 | ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now