2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-3145 | HIGH | 7.5 | 27.9% | Jan 16, 2019 | BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-a... |
| CVE-2017-3144 | HIGH | 7.5 | 72.7% | Jan 16, 2019 | A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool o... |
| CVE-2017-3143 | HIGH | 7.5 | 18.2% | Jan 16, 2019 | An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSI... |
| CVE-2017-3142 | MEDIUM | 5.3 | 5.4% | Jan 16, 2019 | An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSI... |
| CVE-2017-3141 | HIGH | 7.2 | 1.4% | Jan 16, 2019 | The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalatio... |
| CVE-2017-3140 | LOW | 3.7 | 12.1% | Jan 16, 2019 | If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition wh... |
| CVE-2017-3138 | MEDIUM | 6.5 | 5.5% | Jan 16, 2019 | named contains a feature which allows operators to issue commands to a running server by communicating with the server p... |
| CVE-2017-3137 | HIGH | 7.5 | 9.0% | Jan 16, 2019 | Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resourc... |
| CVE-2017-3136 | MEDIUM | 5.9 | 11.1% | Jan 16, 2019 | A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and te... |
| CVE-2017-3135 | HIGH | 7.5 | 17.1% | Jan 16, 2019 | Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an incons... |
| CVE-2017-6921 | — | — | 1.8% | Jan 15, 2019 | In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A sit... |
| CVE-2017-6924 | — | — | 2.1% | Jan 15, 2019 | In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST tha... |
| CVE-2017-6925 | — | — | 3.0% | Jan 15, 2019 | In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwan... |
| CVE-2017-18358 | — | — | 0.9% | Jan 15, 2019 | LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address... |
| CVE-2017-18357 | — | — | 27.1% | Jan 15, 2019 | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t... |
| CVE-2017-18356 | — | — | 2.0% | Jan 15, 2019 | In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the targe... |
| CVE-2017-2411 | — | — | 0.7% | Jan 11, 2019 | In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for ... |
| CVE-2017-13891 | — | — | 0.8% | Jan 11, 2019 | In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management. |
| CVE-2017-13889 | — | — | 1.1% | Jan 11, 2019 | In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic e... |
| CVE-2017-13888 | — | — | 0.8% | Jan 11, 2019 | In iOS before 11.2, a type confusion issue was addressed with improved memory handling. |
| CVE-2017-13887 | — | — | 0.8% | Jan 11, 2019 | In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addre... |
| CVE-2017-13886 | — | — | 0.8% | Jan 11, 2019 | In macOS High Sierra before 10.13.2, an access issue existed with privileged WiFi system configuration. This issue was a... |
| CVE-2017-1002157 | CRITICAL | 9.8 | 2.8% | Jan 10, 2019 | modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execu... |
| CVE-2017-1002152 | MEDIUM | 6.1 | 0.8% | Jan 10, 2019 | Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation o... |
| CVE-2017-3718 | — | — | 0.3% | Jan 10, 2019 | Improper setting of device configuration in system firmware for Intel(R) NUC kits may allow a privileged user to potenti... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now