2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-0371 | HIGH | 7.5 | 1.5% | Feb 18, 2022 | MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to disco... |
| CVE-2017-2488 | HIGH | 7.5 | 0.6% | Dec 23, 2021 | A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implement... |
| CVE-2017-13908 | HIGH | 7.8 | 0.2% | Dec 23, 2021 | An issue in handling file permissions was addressed with improved validation. This issue is fixed in macOS High Sierra 1... |
| CVE-2017-13906 | HIGH | 7.8 | 0.6% | Dec 23, 2021 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13.1,... |
| CVE-2017-13905 | HIGH | 8.1 | 0.9% | Dec 23, 2021 | A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra... |
| CVE-2017-13892 | HIGH | 7.5 | 0.9% | Dec 23, 2021 | An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information... |
| CVE-2017-13880 | HIGH | 7.8 | 0.9% | Dec 23, 2021 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An ... |
| CVE-2017-13835 | HIGH | 7.8 | 0.8% | Dec 23, 2021 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13. A... |
| CVE-2017-5123 | HIGH | 8.8 | 3.7% | Nov 2, 2021 | Insufficient data validation in waitid allowed an user to escape sandboxes on Linux. |
| CVE-2017-16632 | HIGH | 7.5 | 0.7% | Aug 11, 2021 | In SapphireIMS 4097_1, the password in the database is stored in Base64 format. |
| CVE-2017-16630 | HIGH | 8.8 | 0.9% | Aug 11, 2021 | In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installe... |
| CVE-2017-16629 | HIGH | 7.5 | 1.2% | Aug 11, 2021 | In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives ... |
| CVE-2017-18113 | HIGH | 8.8 | 1.8% | Aug 2, 2021 | The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attacker... |
| CVE-2017-20006 | HIGH | 7.8 | 1.2% | Jul 1, 2021 | UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExt... |
| CVE-2017-17677 | HIGH | 8.8 | 1.3% | May 19, 2021 | BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports... |
| CVE-2017-20002 | HIGH | 7.8 | 0.4% | Mar 17, 2021 | The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/secu... |
| CVE-2017-20001 | HIGH | 7.5 | 0.4% | Jan 1, 2021 | The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-C... |
| CVE-2017-2910 | HIGH | 8.8 | 2.1% | Dec 2, 2020 | An exploitable Out-of-bounds Write vulnerability exists in the xls_addCell function of libxls 2.0. A specially crafted x... |
| CVE-2017-15685 | HIGH | 8.6 | 1.7% | Nov 27, 2020 | Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to creat... |
| CVE-2017-15684 | HIGH | 7.5 | 2.0% | Nov 27, 2020 | Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view ... |
| CVE-2017-15683 | HIGH | 8.6 | 1.5% | Nov 27, 2020 | In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that... |
| CVE-2017-18926 | HIGH | 7.1 | 3.1% | Nov 6, 2020 | raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maxi... |
| CVE-2017-18924 | HIGH | 7.5 | 2.2% | Oct 4, 2020 | oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorizatio... |
| CVE-2017-18923 | HIGH | 7.5 | 1.2% | Jul 29, 2020 | beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with crede... |
| CVE-2017-18917 | HIGH | 7.5 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitation... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now