2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-18642MEDIUM6.5Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to...
CVE-2017-18641HIGH8.1In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running ...
CVE-2017-3149Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2017-3148Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2017-3147Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2017-3146Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2017-16112Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:CVE-2017-15010. Reason: This candidate is a reservation du...
CVE-2017-14807HIGH8.1An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-s...
CVE-2017-14806MEDIUM5.9A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MI...
CVE-2017-3211MEDIUM5.3Yopify, an e-commerce notification plugin, up to April 06, 2017, leaks the first name, last initial, city, and recent pu...
CVE-2017-16778MEDIUM4.6An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-...
CVE-2017-18107MEDIUM6.5Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify...
CVE-2017-18640HIGH7.5The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-...
CVE-2017-12945HIGH8.8Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authen...
CVE-2017-7399HIGH8.8Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager us...
CVE-2017-17224HIGH8.8Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference v...
CVE-2017-18639MEDIUM6.1Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, ...
CVE-2017-5333HIGH7.8Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 al...
CVE-2017-5332HIGH7.8The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, wh...
CVE-2017-5331HIGH7.8Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to c...
CVE-2017-3989Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2017-2859Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2017-2778Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2017-2776Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2017-16993Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now