2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7562 | MEDIUM | 6.5 | 3.3% | Jul 26, 2018 | An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of cli... |
| CVE-2017-7558 | MEDIUM | 5.1 | 3.8% | Jul 26, 2018 | A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sc... |
| CVE-2017-7545 | MEDIUM | 6.5 | 2.8% | Jul 26, 2018 | It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while ... |
| CVE-2017-7538 | LOW | 3.5 | 0.7% | Jul 26, 2018 | A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user ... |
| CVE-2017-2589 | HIGH | 8.7 | 0.9% | Jul 26, 2018 | It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cook... |
| CVE-2017-7543 | MEDIUM | 5.3 | 1.8% | Jul 26, 2018 | A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1... |
| CVE-2017-7539 | MEDIUM | 5.3 | 5.5% | Jul 26, 2018 | An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection... |
| CVE-2017-2664 | MEDIUM | 6.5 | 1.3% | Jul 26, 2018 | CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the ra... |
| CVE-2017-12610 | — | — | 3.0% | Jul 26, 2018 | In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a m... |
| CVE-2017-7537 | MEDIUM | 5.9 | 1.5% | Jul 26, 2018 | It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pk... |
| CVE-2017-7535 | MEDIUM | 6.1 | 1.5% | Jul 26, 2018 | foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting t... |
| CVE-2017-7530 | HIGH | 8.8 | 1.7% | Jul 26, 2018 | In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing... |
| CVE-2017-7526 | MEDIUM | 6.1 | 3.9% | Jul 26, 2018 | libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 ... |
| CVE-2017-2637 | CRITICAL | 9.9 | 4.8% | Jul 26, 2018 | A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-mi... |
| CVE-2017-10937 | — | — | 1.3% | Jul 25, 2018 | SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers t... |
| CVE-2017-10936 | — | — | 1.3% | Jul 25, 2018 | SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to ex... |
| CVE-2017-10935 | — | — | 1.3% | Jul 25, 2018 | All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the or... |
| CVE-2017-10934 | — | — | 3.1% | Jul 25, 2018 | All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the ... |
| CVE-2017-3226 | — | — | 0.3% | Jul 24, 2018 | Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of D... |
| CVE-2017-3225 | — | — | 0.3% | Jul 24, 2018 | Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. For devices utilizing this... |
| CVE-2017-3224 | — | — | 1.1% | Jul 24, 2018 | Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency... |
| CVE-2017-3223 | — | — | 5.3% | Jul 24, 2018 | Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web i... |
| CVE-2017-3217 | — | — | 2.0% | Jul 24, 2018 | CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no pas... |
| CVE-2017-3210 | — | — | 0.9% | Jul 24, 2018 | Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations wh... |
| CVE-2017-3209 | HIGH | 8.1 | 1.2% | Jul 24, 2018 | The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permis... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now