2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1000473Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are pars...
CVE-2017-1000472The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restri...
CVE-2017-1000471EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in me...
CVE-2017-1000470EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulti...
CVE-2017-1000469Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in ...
CVE-2017-1000462BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result i...
CVE-2017-1000461Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the ...
CVE-2017-1000460In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of ...
CVE-2017-1000483Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an ...
CVE-2017-1000482A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this execu...
CVE-2017-1000481When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter...
CVE-2017-1000480Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resou...
CVE-2017-1000479pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged e...
CVE-2017-1000478ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitr...
CVE-2017-1000477XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.
CVE-2017-1000476ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which al...
CVE-2017-1000490Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic...
CVE-2017-1000489Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email addres...
CVE-2017-1000488Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page ...
CVE-2017-8049Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-8043Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-8042Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-8030Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-8029Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-8027Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now