2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7989 | — | — | 1.0% | Apr 25, 2017 | In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf f... |
| CVE-2017-7988 | — | — | 1.0% | Apr 25, 2017 | In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of ... |
| CVE-2017-7987 | — | — | 0.8% | Apr 25, 2017 | In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabiliti... |
| CVE-2017-7986 | — | — | 0.8% | Apr 25, 2017 | In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabi... |
| CVE-2017-7985 | — | — | 1.3% | Apr 25, 2017 | In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabiliti... |
| CVE-2017-7984 | — | — | 0.8% | Apr 25, 2017 | In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component. |
| CVE-2017-7983 | — | — | 1.1% | Apr 25, 2017 | In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the ... |
| CVE-2017-1274 | — | — | 6.7% | Apr 25, 2017 | IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated ... |
| CVE-2017-1149 | — | — | 1.5% | Apr 25, 2017 | IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Inje... |
| CVE-2017-8110 | CRITICAL | 10 | 1.1% | Apr 25, 2017 | www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kan... |
| CVE-2017-8109 | — | — | 0.4% | Apr 25, 2017 | The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master witho... |
| CVE-2017-5625 | — | — | 0.3% | Apr 25, 2017 | In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partiall... |
| CVE-2017-7477 | HIGH | 7 | 0.4% | Apr 25, 2017 | Heap-based buffer overflow in drivers/net/macsec.c in the MACsec module in the Linux kernel through 4.10.12 allows attac... |
| CVE-2017-7221 | — | — | 4.2% | Apr 25, 2017 | OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote aut... |
| CVE-2017-5051 | — | — | 0.8% | Apr 25, 2017 | An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for A... |
| CVE-2017-5050 | — | — | 0.8% | Apr 25, 2017 | An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for A... |
| CVE-2017-5049 | — | — | 0.8% | Apr 25, 2017 | An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for A... |
| CVE-2017-5048 | — | — | 0.8% | Apr 25, 2017 | An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for A... |
| CVE-2017-5047 | — | — | 0.8% | Apr 25, 2017 | An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for A... |
| CVE-2017-8106 | — | — | 0.3% | Apr 24, 2017 | The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS us... |
| CVE-2017-5046 | MEDIUM | 4.3 | 1.3% | Apr 24, 2017 | V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android had insufficient pol... |
| CVE-2017-5045 | MEDIUM | 6.1 | 1.2% | Apr 24, 2017 | XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed det... |
| CVE-2017-5044 | MEDIUM | 6.3 | 2.4% | Apr 24, 2017 | Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and... |
| CVE-2017-5043 | HIGH | 8.8 | 1.3% | Apr 24, 2017 | Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, wh... |
| CVE-2017-5042 | MEDIUM | 5.7 | 0.4% | Apr 24, 2017 | Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to si... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now