2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1349 | — | — | 0.3% | Jun 23, 2017 | IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could ... |
| CVE-2017-1348 | — | — | 0.7% | Jun 23, 2017 | IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users ... |
| CVE-2017-1347 | — | — | 1.5% | Jun 23, 2017 | IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-... |
| CVE-2017-1302 | — | — | 0.3% | Jun 23, 2017 | IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper acc... |
| CVE-2017-1193 | — | — | 1.2% | Jun 23, 2017 | IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET requ... |
| CVE-2017-1132 | — | — | 0.7% | Jun 23, 2017 | IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users ... |
| CVE-2017-1131 | — | — | 1.4% | Jun 23, 2017 | IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by us... |
| CVE-2017-3948 | — | — | 0.5% | Jun 23, 2017 | Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.... |
| CVE-2017-8813 | — | — | — | Jun 23, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-8831. Reason: This candidate is a duplicate of... |
| CVE-2017-9356 | — | — | 0.8% | Jun 23, 2017 | Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results... |
| CVE-2017-9776 | — | — | 2.0% | Jun 22, 2017 | Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote at... |
| CVE-2017-9775 | — | — | 4.3% | Jun 22, 2017 | Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of s... |
| CVE-2017-2782 | MEDIUM | 6.5 | 1.0% | Jun 22, 2017 | An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.... |
| CVE-2017-2781 | CRITICAL | 9.8 | 2.3% | Jun 22, 2017 | An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure M... |
| CVE-2017-2780 | CRITICAL | 9.8 | 2.3% | Jun 22, 2017 | An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure M... |
| CVE-2017-0897 | — | — | 4.0% | Jun 22, 2017 | ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successf... |
| CVE-2017-1326 | — | — | 0.8% | Jun 22, 2017 | IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to u... |
| CVE-2017-9424 | — | — | 2.7% | Jun 22, 2017 | IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of Typ... |
| CVE-2017-9815 | — | — | 1.6% | Jun 22, 2017 | In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which ... |
| CVE-2017-0176 | — | — | 45.9% | Jun 22, 2017 | A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 th... |
| CVE-2017-3631 | — | — | 6.0% | Jun 22, 2017 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio... |
| CVE-2017-3630 | — | — | 4.5% | Jun 22, 2017 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t... |
| CVE-2017-3629 | — | — | 5.1% | Jun 22, 2017 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t... |
| CVE-2017-9807 | — | — | 4.9% | Jun 22, 2017 | An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/co... |
| CVE-2017-9782 | — | — | 1.6% | Jun 21, 2017 | JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) v... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now