2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17675 | MEDIUM | 5.3 | 1.1% | May 19, 2021 | BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowi... |
| CVE-2017-20004 | MEDIUM | 5.9 | 0.8% | Apr 14, 2021 | In the standard library in Rust before 1.19.0, there is a synchronization problem in the MutexGuard object. MutexGuards ... |
| CVE-2017-15686 | MEDIUM | 6.1 | 1.0% | Nov 27, 2020 | Crafter CMS Crafter Studio 3.0.1 is affected by: Cross Site Scripting (XSS), which allows remote attackers to steal user... |
| CVE-2017-15682 | MEDIUM | 6.1 | 0.7% | Nov 27, 2020 | In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in... |
| CVE-2017-15680 | MEDIUM | 6.5 | 0.7% | Nov 27, 2020 | In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modi... |
| CVE-2017-18925 | MEDIUM | 5.5 | 0.4% | Oct 26, 2020 | opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and ... |
| CVE-2017-17477 | MEDIUM | 6.1 | 0.8% | Sep 25, 2020 | Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface vi... |
| CVE-2017-18112 | MEDIUM | 6.5 | 1.0% | Aug 5, 2020 | Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Informati... |
| CVE-2017-1712 | MEDIUM | 5.9 | 0.7% | Jul 1, 2020 | "A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker... |
| CVE-2017-1659 | MEDIUM | 6.1 | 0.7% | Jul 1, 2020 | "HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to st... |
| CVE-2017-18921 | MEDIUM | 6.1 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page. |
| CVE-2017-18919 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team ... |
| CVE-2017-18918 | MEDIUM | 4.9 | 0.5% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate... |
| CVE-2017-18916 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor ... |
| CVE-2017-18914 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page... |
| CVE-2017-18913 | MEDIUM | 6.1 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page. |
| CVE-2017-18907 | MEDIUM | 6.1 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header. |
| CVE-2017-18905 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider... |
| CVE-2017-18910 | MEDIUM | 4.3 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links... |
| CVE-2017-18904 | MEDIUM | 6.1 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file. |
| CVE-2017-18902 | MEDIUM | 5.3 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invit... |
| CVE-2017-18901 | MEDIUM | 5.3 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team inv... |
| CVE-2017-18899 | MEDIUM | 5.3 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting. |
| CVE-2017-18898 | MEDIUM | 5.3 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially ca... |
| CVE-2017-18897 | MEDIUM | 6.1 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider.... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now