2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-0371HIGH7.5MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to disco...
CVE-2017-2488HIGH7.5A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implement...
CVE-2017-13908HIGH7.8An issue in handling file permissions was addressed with improved validation. This issue is fixed in macOS High Sierra 1...
CVE-2017-13906HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13.1,...
CVE-2017-13905HIGH8.1A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra...
CVE-2017-13892HIGH7.5An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information...
CVE-2017-13880HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An ...
CVE-2017-13835HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13. A...
CVE-2017-5123HIGH8.8Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
CVE-2017-16632HIGH7.5In SapphireIMS 4097_1, the password in the database is stored in Base64 format.
CVE-2017-16630HIGH8.8In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installe...
CVE-2017-16629HIGH7.5In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives ...
CVE-2017-18113HIGH8.8The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attacker...
CVE-2017-20006HIGH7.8UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExt...
CVE-2017-17677HIGH8.8BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports...
CVE-2017-20002HIGH7.8The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/secu...
CVE-2017-20001HIGH7.5The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-C...
CVE-2017-2910HIGH8.8An exploitable Out-of-bounds Write vulnerability exists in the xls_addCell function of libxls 2.0. A specially crafted x...
CVE-2017-15685HIGH8.6Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to creat...
CVE-2017-15684HIGH7.5Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view ...
CVE-2017-15683HIGH8.6In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that...
CVE-2017-18926HIGH7.1raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maxi...
CVE-2017-18924HIGH7.5oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorizatio...
CVE-2017-18923HIGH7.5beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with crede...
CVE-2017-18917HIGH7.5An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitation...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now