2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-0919 | — | — | 1.1% | Jul 3, 2018 | GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass iss... |
| CVE-2017-0913 | — | — | 0.3% | Jul 3, 2018 | Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note... |
| CVE-2017-1299 | — | — | 0.7% | Jul 3, 2018 | IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5... |
| CVE-2017-17317 | — | — | 1.0% | Jul 2, 2018 | Common Open Policy Service Protocol (COPS) module in Huawei USG6300 V100R001C10; V100R001C20; V100R001C30; V500R001C00; ... |
| CVE-2017-17316 | — | — | 1.2% | Jul 2, 2018 | Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; ... |
| CVE-2017-17175 | — | — | 0.4% | Jul 2, 2018 | Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) h... |
| CVE-2017-16859 | — | — | 2.5% | Jun 28, 2018 | The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 a... |
| CVE-2017-16726 | — | — | 0.5% | Jun 27, 2018 | Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments.... |
| CVE-2017-16718 | — | — | 0.4% | Jun 27, 2018 | Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environment... |
| CVE-2017-7656 | — | — | 6.4% | Jun 26, 2018 | In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC261... |
| CVE-2017-9312 | — | — | 4.4% | Jun 25, 2018 | Improperly implemented option-field processing in the TCP/IP stack on Allen-Bradley L30ERMS safety devices v30 and earli... |
| CVE-2017-7568 | — | — | 1.4% | Jun 22, 2018 | NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account i... |
| CVE-2017-13072 | — | — | 0.8% | Jun 21, 2018 | Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4... |
| CVE-2017-17062 | — | — | 3.7% | Jun 16, 2018 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4... |
| CVE-2017-18169 | — | — | 0.1% | Jun 15, 2018 | User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android... |
| CVE-2017-12070 | — | — | 1.0% | Jun 14, 2018 | Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code. |
| CVE-2017-17309 | — | — | 7.3% | Jun 14, 2018 | Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received ... |
| CVE-2017-17173 | — | — | 1.0% | Jun 14, 2018 | Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL... |
| CVE-2017-17172 | — | — | 0.2% | Jun 14, 2018 | Huawei smart phones LYO-L21 with software LYO-L21C479B107, LYO-L21C479B107 have a privilege escalation vulnerability. An... |
| CVE-2017-17443 | — | — | 0.9% | Jun 13, 2018 | OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that... |
| CVE-2017-11672 | — | — | 0.3% | Jun 13, 2018 | The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double ... |
| CVE-2017-15695 | — | — | 2.6% | Jun 13, 2018 | When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privil... |
| CVE-2017-16652 | — | — | 0.9% | Jun 13, 2018 | An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.1... |
| CVE-2017-18070 | — | — | 0.2% | Jun 12, 2018 | In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of va... |
| CVE-2017-15857 | — | — | 0.2% | Jun 12, 2018 | In the camera driver, an out-of-bounds access can occur due to an error in copying region params from user space in all ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now