2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-18642 | MEDIUM | 6.5 | 0.6% | Feb 10, 2020 | Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to... |
| CVE-2017-18641 | HIGH | 8.1 | 1.3% | Feb 10, 2020 | In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running ... |
| CVE-2017-3149 | — | — | — | Feb 7, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2017-3148 | — | — | — | Feb 7, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2017-3147 | — | — | — | Feb 7, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2017-3146 | — | — | — | Feb 7, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2017-16112 | — | — | — | Jan 27, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:CVE-2017-15010. Reason: This candidate is a reservation du... |
| CVE-2017-14807 | HIGH | 8.1 | 1.0% | Jan 27, 2020 | An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-s... |
| CVE-2017-14806 | MEDIUM | 5.9 | 0.4% | Jan 27, 2020 | A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MI... |
| CVE-2017-3211 | MEDIUM | 5.3 | 0.8% | Jan 15, 2020 | Yopify, an e-commerce notification plugin, up to April 06, 2017, leaks the first name, last initial, city, and recent pu... |
| CVE-2017-16778 | MEDIUM | 4.6 | 0.6% | Dec 24, 2019 | An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-... |
| CVE-2017-18107 | MEDIUM | 6.5 | 0.4% | Dec 17, 2019 | Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify... |
| CVE-2017-18640 | HIGH | 7.5 | 26.7% | Dec 12, 2019 | The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-... |
| CVE-2017-12945 | HIGH | 8.8 | 17.4% | Nov 27, 2019 | Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authen... |
| CVE-2017-7399 | HIGH | 8.8 | 0.9% | Nov 26, 2019 | Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager us... |
| CVE-2017-17224 | HIGH | 8.8 | 0.4% | Nov 12, 2019 | Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference v... |
| CVE-2017-18639 | MEDIUM | 6.1 | 0.9% | Nov 6, 2019 | Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, ... |
| CVE-2017-5333 | HIGH | 7.8 | 2.2% | Nov 4, 2019 | Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 al... |
| CVE-2017-5332 | HIGH | 7.8 | 2.1% | Nov 4, 2019 | The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, wh... |
| CVE-2017-5331 | HIGH | 7.8 | 0.5% | Nov 4, 2019 | Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to c... |
| CVE-2017-3989 | — | — | — | Nov 4, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2017-2859 | — | — | — | Oct 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2017-2778 | — | — | — | Oct 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2017-2776 | — | — | — | Oct 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2017-16993 | — | — | — | Oct 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now