2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6921 | — | — | 1.8% | Jan 15, 2019 | In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A sit... |
| CVE-2017-6924 | — | — | 2.1% | Jan 15, 2019 | In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST tha... |
| CVE-2017-6925 | — | — | 3.0% | Jan 15, 2019 | In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwan... |
| CVE-2017-18358 | — | — | 0.9% | Jan 15, 2019 | LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address... |
| CVE-2017-18357 | — | — | 27.1% | Jan 15, 2019 | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t... |
| CVE-2017-18356 | — | — | 2.0% | Jan 15, 2019 | In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the targe... |
| CVE-2017-2411 | — | — | 0.7% | Jan 11, 2019 | In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for ... |
| CVE-2017-13891 | — | — | 0.8% | Jan 11, 2019 | In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management. |
| CVE-2017-13889 | — | — | 1.1% | Jan 11, 2019 | In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic e... |
| CVE-2017-13888 | — | — | 0.8% | Jan 11, 2019 | In iOS before 11.2, a type confusion issue was addressed with improved memory handling. |
| CVE-2017-13887 | — | — | 0.8% | Jan 11, 2019 | In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addre... |
| CVE-2017-13886 | — | — | 0.8% | Jan 11, 2019 | In macOS High Sierra before 10.13.2, an access issue existed with privileged WiFi system configuration. This issue was a... |
| CVE-2017-3718 | — | — | 0.3% | Jan 10, 2019 | Improper setting of device configuration in system firmware for Intel(R) NUC kits may allow a privileged user to potenti... |
| CVE-2017-15428 | — | — | 18.1% | Jan 9, 2019 | Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in ... |
| CVE-2017-15405 | — | — | 0.2% | Jan 9, 2019 | Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a pers... |
| CVE-2017-15404 | — | — | 0.2% | Jan 9, 2019 | An ability to process crash dumps under root privileges and inappropriate symlinks handling could lead to a local privil... |
| CVE-2017-15403 | — | — | 0.6% | Jan 9, 2019 | Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google... |
| CVE-2017-15402 | — | — | 0.6% | Jan 9, 2019 | Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any o... |
| CVE-2017-15401 | — | — | 2.0% | Jan 9, 2019 | A memory corruption bug in WebAssembly could lead to out of bounds read and write through V8 in WebAssembly in Google Ch... |
| CVE-2017-18330 | — | — | 0.2% | Jan 3, 2019 | Buffer overflow in AES-CCM and AES-GCM encryption via initialization vector in snapdragon automobile, snapdragon mobile ... |
| CVE-2017-18329 | — | — | 0.2% | Jan 3, 2019 | Possible Buffer overflow when transmitting an RTP packet in snapdragon automobile and snapdragon wear in versions MDM961... |
| CVE-2017-18328 | — | — | 0.2% | Jan 3, 2019 | Use after free in QSH client rule processing in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9... |
| CVE-2017-18327 | — | — | 0.2% | Jan 3, 2019 | Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile a... |
| CVE-2017-18326 | — | — | 0.2% | Jan 3, 2019 | Cryptographic keys are printed in modem debug messages in snapdragon mobile and snapdragon wear in versions MDM9607, MDM... |
| CVE-2017-18324 | — | — | 0.2% | Jan 3, 2019 | Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now