2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-18027 | — | — | 3.1% | Jan 12, 2018 | In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which al... |
| CVE-2017-16743 | — | — | 3.1% | Jan 12, 2018 | An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products runnin... |
| CVE-2017-16741 | — | — | 1.2% | Jan 12, 2018 | An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running ... |
| CVE-2017-16739 | — | — | 2.3% | Jan 12, 2018 | An issue was discovered in WECON Technology LEVI Studio HMI Editor v1.8.29 and prior. Specially-crafted malicious files ... |
| CVE-2017-16737 | — | — | 1.1% | Jan 12, 2018 | An issue was discovered in WECON Technology LEVI Studio HMI Editor v1.8.29 and prior. A specially-crafted malicious file... |
| CVE-2017-14030 | — | — | 0.4% | Jan 12, 2018 | An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an... |
| CVE-2017-18014 | — | — | 2.3% | Jan 12, 2018 | An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthen... |
| CVE-2017-17970 | — | — | 5.4% | Jan 12, 2018 | Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1... |
| CVE-2017-16887 | — | — | 36.6% | Jan 12, 2018 | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact... |
| CVE-2017-16886 | — | — | 7.1% | Jan 12, 2018 | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact... |
| CVE-2017-16885 | — | — | 33.5% | Jan 12, 2018 | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining informati... |
| CVE-2017-0869 | — | — | 0.2% | Jan 12, 2018 | NVIDIA driver contains an integer overflow vulnerability which could cause a use after free and possibly lead to an elev... |
| CVE-2017-2158 | — | — | 0.6% | Jan 12, 2018 | Improper verification when expanding ZIP64 archives in Lhaplus versions 1.73 and earlier may lead to unintended contents... |
| CVE-2017-16864 | — | — | 1.2% | Jan 12, 2018 | The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or Jav... |
| CVE-2017-16862 | — | — | 0.6% | Jan 12, 2018 | The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming ... |
| CVE-2017-14594 | — | — | 1.0% | Jan 12, 2018 | The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 a... |
| CVE-2017-16736 | — | — | 1.8% | Jan 12, 2018 | An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. We... |
| CVE-2017-16732 | — | — | 1.4% | Jan 12, 2018 | A use-after-free issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows an unauthenticated ... |
| CVE-2017-1740 | — | — | 0.7% | Jan 11, 2018 | IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vu... |
| CVE-2017-1739 | — | — | 0.7% | Jan 11, 2018 | IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerabi... |
| CVE-2017-1681 | — | — | 0.4% | Jan 11, 2018 | IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitiv... |
| CVE-2017-1478 | — | — | 0.4% | Jan 11, 2018 | IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on t... |
| CVE-2017-18016 | — | — | 5.5% | Jan 11, 2018 | Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat... |
| CVE-2017-15637 | — | — | 4.2% | Jan 11, 2018 | TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje... |
| CVE-2017-15636 | — | — | 4.2% | Jan 11, 2018 | TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now