2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-7518MEDIUM5.5A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EF...
CVE-2017-7514MEDIUM4.3A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before vers...
CVE-2017-7482HIGH7.8In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the si...
CVE-2017-15118HIGH8.3A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client...
CVE-2017-2663HIGH8.2It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1....
CVE-2017-2652It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 fo...
CVE-2017-2650It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for...
CVE-2017-2649It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of...
CVE-2017-2648MEDIUM6.8It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling ...
CVE-2017-15101HIGH7.8A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. ...
CVE-2017-15097MEDIUM6.5Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to th...
CVE-2017-2634HIGH7.5It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used th...
CVE-2017-2633MEDIUM5.4An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This fla...
CVE-2017-2632MEDIUM4.9A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create ...
CVE-2017-2629MEDIUM4.3curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the ...
CVE-2017-2626MEDIUM5.2It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially us...
CVE-2017-2620MEDIUM5.5Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds ...
CVE-2017-2618MEDIUM5.5A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An...
CVE-2017-2616MEDIUM5.5A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local ...
CVE-2017-7463MEDIUM6.1JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, i...
CVE-2017-2674MEDIUM6.1JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw...
CVE-2017-2658LOW2.6It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data...
CVE-2017-2653MEDIUM4.1A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead...
CVE-2017-2651LOW3.7jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send ema...
CVE-2017-2646HIGH7.5It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, t...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now