2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-3145HIGH7.5BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-a...
CVE-2017-3144HIGH7.5A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool o...
CVE-2017-3143HIGH7.5An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSI...
CVE-2017-3142MEDIUM5.3An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSI...
CVE-2017-3141HIGH7.2The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalatio...
CVE-2017-3140LOW3.7If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition wh...
CVE-2017-3138MEDIUM6.5named contains a feature which allows operators to issue commands to a running server by communicating with the server p...
CVE-2017-3137HIGH7.5Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resourc...
CVE-2017-3136MEDIUM5.9A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and te...
CVE-2017-3135HIGH7.5Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an incons...
CVE-2017-6921In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A sit...
CVE-2017-6924In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST tha...
CVE-2017-6925In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwan...
CVE-2017-18358LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address...
CVE-2017-18357Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t...
CVE-2017-18356In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the targe...
CVE-2017-2411In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for ...
CVE-2017-13891In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.
CVE-2017-13889In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic e...
CVE-2017-13888In iOS before 11.2, a type confusion issue was addressed with improved memory handling.
CVE-2017-13887In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addre...
CVE-2017-13886In macOS High Sierra before 10.13.2, an access issue existed with privileged WiFi system configuration. This issue was a...
CVE-2017-1002157CRITICAL9.8modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execu...
CVE-2017-1002152MEDIUM6.1Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation o...
CVE-2017-3718Improper setting of device configuration in system firmware for Intel(R) NUC kits may allow a privileged user to potenti...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now