2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-7562MEDIUM6.5An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of cli...
CVE-2017-7558MEDIUM5.1A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sc...
CVE-2017-7545MEDIUM6.5It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while ...
CVE-2017-7538LOW3.5A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user ...
CVE-2017-2589HIGH8.7It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cook...
CVE-2017-7543MEDIUM5.3A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1...
CVE-2017-7539MEDIUM5.3An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection...
CVE-2017-2664MEDIUM6.5CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the ra...
CVE-2017-12610In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a m...
CVE-2017-7537MEDIUM5.9It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pk...
CVE-2017-7535MEDIUM6.1foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting t...
CVE-2017-7530HIGH8.8In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing...
CVE-2017-7526MEDIUM6.1libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 ...
CVE-2017-2637CRITICAL9.9A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-mi...
CVE-2017-10937SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers t...
CVE-2017-10936SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to ex...
CVE-2017-10935All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the or...
CVE-2017-10934All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the ...
CVE-2017-3226Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of D...
CVE-2017-3225Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. For devices utilizing this...
CVE-2017-3224Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency...
CVE-2017-3223Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web i...
CVE-2017-3217CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no pas...
CVE-2017-3210Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations wh...
CVE-2017-3209HIGH8.1The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permis...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now