2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-7528MEDIUM5.2Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that ...
CVE-2017-2662MEDIUM4.3A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a rep...
CVE-2017-7513MEDIUM5.4It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 serv...
CVE-2017-17312Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V...
CVE-2017-17311Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V...
CVE-2017-17305Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V...
CVE-2017-1753MEDIUM5.4Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, whi...
CVE-2017-16748An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework ...
CVE-2017-16744A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior...
CVE-2017-1732MEDIUM4.3IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization token...
CVE-2017-13108DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encry...
CVE-2017-13107HIGH7.5Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption. Data sto...
CVE-2017-13106Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-c...
CVE-2017-13105Hi Security Virus Cleaner - Antivirus, Booster, 3.7.1.1329, 2017-09-13, Android application accepts all SSL certificates...
CVE-2017-13104Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key...
CVE-2017-13103Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2017-13102Gameloft Asphalt Xtreme: Offroad Rally Racing, 1.6.0, 2017-08-13, iOS application uses a hard-coded key for encryption. ...
CVE-2017-13101Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for en...
CVE-2017-13100DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored ...
CVE-2017-7500HIGH7.3It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directo...
CVE-2017-15138MEDIUM5The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges...
CVE-2017-1749MEDIUM5.3IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthe...
CVE-2017-1286Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be...
CVE-2017-2654LOW3.7jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to...
CVE-2017-16790An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submi...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now