2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1349IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could ...
CVE-2017-1348IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users ...
CVE-2017-1347IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-...
CVE-2017-1302IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper acc...
CVE-2017-1193IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET requ...
CVE-2017-1132IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users ...
CVE-2017-1131IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by us...
CVE-2017-3948Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0....
CVE-2017-8813Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-8831. Reason: This candidate is a duplicate of...
CVE-2017-9356Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results...
CVE-2017-9776Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote at...
CVE-2017-9775Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of s...
CVE-2017-2782MEDIUM6.5An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b....
CVE-2017-2781CRITICAL9.8An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure M...
CVE-2017-2780CRITICAL9.8An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure M...
CVE-2017-0897ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successf...
CVE-2017-1326IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to u...
CVE-2017-9424IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of Typ...
CVE-2017-9815In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which ...
CVE-2017-0176A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 th...
CVE-2017-3631Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio...
CVE-2017-3630Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t...
CVE-2017-3629Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t...
CVE-2017-9807An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/co...
CVE-2017-9782JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) v...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now