2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17833 | — | — | 3.9% | Apr 23, 2018 | OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itse... |
| CVE-2017-13073 | — | — | 0.8% | Apr 23, 2018 | Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier ... |
| CVE-2017-1786 | — | — | 1.1% | Apr 23, 2018 | IBM WebSphere MQ 8.0 through 8.0.0.8 and 9.0 through 9.0.4 under special circumstances could allow an authenticated user... |
| CVE-2017-1764 | — | — | 0.3% | Apr 23, 2018 | IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain... |
| CVE-2017-1701 | — | — | 0.5% | Apr 23, 2018 | IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores credentials for users using ... |
| CVE-2017-1486 | — | — | 0.9% | Apr 23, 2018 | IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2 is vulnerable to cross-site scripting. This vulnerab... |
| CVE-2017-1473 | — | — | 0.9% | Apr 23, 2018 | IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptogr... |
| CVE-2017-17902 | — | — | 1.1% | Apr 22, 2018 | SQL Injection exists in Kliqqi CMS 3.5.2 via the randkey parameter of a new story at the pligg/story.php?title= URI. |
| CVE-2017-17889 | — | — | 0.5% | Apr 22, 2018 | Kliqqi CMS 3.5.2 has XSS via a crafted group name in pligg/groups.php, a crafted Homepage string in a profile, or a craf... |
| CVE-2017-15640 | — | — | 0.7% | Apr 21, 2018 | app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter. |
| CVE-2017-2825 | — | — | 4.4% | Apr 20, 2018 | In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks... |
| CVE-2017-8315 | — | — | 1.7% | Apr 20, 2018 | Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity atta... |
| CVE-2017-3776 | — | — | 1.1% | Apr 19, 2018 | Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP chann... |
| CVE-2017-3774 | — | — | 1.3% | Apr 19, 2018 | A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (I... |
| CVE-2017-17313 | — | — | 0.6% | Apr 19, 2018 | The inputhub driver of HUAWEI P9 Lite mobile phones with Versions earlier than VNS-L21C02B341, Versions earlier than VNS... |
| CVE-2017-17310 | — | — | 1.3% | Apr 19, 2018 | Electronic Numbers to URI Mapping (ENUM) module in some Huawei products DP300 V500R002C00, RP200 V600R006C00, TE30 V100R... |
| CVE-2017-18261 | — | — | 0.3% | Apr 19, 2018 | The arch_timer_reg_read_stable macro in arch/arm64/include/asm/arch_timer.h in the Linux kernel before 4.13 allows local... |
| CVE-2017-9638 | — | — | 3.6% | Apr 17, 2018 | Mitsubishi E-Designer, Version 7.52 Build 344 contains six code sections which may be exploited to overwrite the stack. ... |
| CVE-2017-9636 | — | — | 3.6% | Apr 17, 2018 | Mitsubishi E-Designer, Version 7.52 Build 344 contains five code sections which may be exploited to overwrite the heap. ... |
| CVE-2017-9634 | — | — | 3.6% | Apr 17, 2018 | Mitsubishi E-Designer, Version 7.52 Build 344 contains two code sections which may be exploited to allow an attacker to ... |
| CVE-2017-6020 | — | — | 8.7% | Apr 17, 2018 | Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237... |
| CVE-2017-12701 | — | — | 1.3% | Apr 17, 2018 | BMC Medical Luna CPAP Machines released prior to July 1, 2017, contain an improper input validation vulnerability which ... |
| CVE-2017-6323 | — | — | 0.5% | Apr 16, 2018 | The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML... |
| CVE-2017-10140 | — | — | 0.6% | Apr 16, 2018 | Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain ... |
| CVE-2017-0372 | — | — | 11.7% | Apr 13, 2018 | Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in mul... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now