2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-3213 | — | — | 0.9% | May 5, 2017 | The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows... |
| CVE-2017-3212 | MEDIUM | 5.9 | 0.8% | May 5, 2017 | The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from S... |
| CVE-2017-8786 | — | — | 4.1% | May 5, 2017 | pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly... |
| CVE-2017-8768 | — | — | 8.3% | May 4, 2017 | Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It... |
| CVE-2017-3733 | — | — | 12.6% | May 4, 2017 | During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handsh... |
| CVE-2017-3732 | MEDIUM | 5.9 | 15.9% | May 4, 2017 | There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 be... |
| CVE-2017-3731 | HIGH | 7.5 | 57.6% | May 4, 2017 | If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet... |
| CVE-2017-3730 | — | — | 55.3% | May 4, 2017 | In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this ... |
| CVE-2017-8778 | — | — | 0.9% | May 4, 2017 | GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment... |
| CVE-2017-8780 | — | — | 0.6% | May 4, 2017 | GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demo... |
| CVE-2017-8779 | — | — | 81.9% | May 4, 2017 | rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider t... |
| CVE-2017-8295 | — | — | 26.7% | May 4, 2017 | WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for re... |
| CVE-2017-4983 | — | — | 0.4% | May 4, 2017 | EMC Data Domain OS 5.2 through 5.7 before 5.7.3.0 and 6.0 before 6.0.1.0 is affected by a privilege escalation vulnerabi... |
| CVE-2017-8776 | HIGH | 7.5 | 0.9% | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 h... |
| CVE-2017-8775 | CRITICAL | 9.8 | 1.2% | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 a... |
| CVE-2017-8774 | CRITICAL | 9.8 | 1.2% | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 a... |
| CVE-2017-8773 | CRITICAL | 9.8 | 2.3% | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 a... |
| CVE-2017-8765 | — | — | 1.6% | May 4, 2017 | The function named ReadICONImage in coders\icon.c in ImageMagick 7.0.5-5 has a memory leak vulnerability which can cause... |
| CVE-2017-8763 | — | — | 0.8% | May 4, 2017 | Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 a... |
| CVE-2017-8762 | — | — | 0.5% | May 3, 2017 | GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribu... |
| CVE-2017-6629 | — | — | 2.5% | May 3, 2017 | A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attack... |
| CVE-2017-6628 | — | — | 1.7% | May 3, 2017 | A vulnerability in SMART-SSL Accelerator functionality for Cisco Wide Area Application Services (WAAS) 6.2.1, 6.2.1a, an... |
| CVE-2017-6626 | — | — | 2.3% | May 3, 2017 | A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and... |
| CVE-2017-6625 | HIGH | 7.1 | 1.8% | May 3, 2017 | A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerabili... |
| CVE-2017-6624 | — | — | 1.4% | May 3, 2017 | A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remot... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now