2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14174 | MEDIUM | 6.5 | 2.2% | Sep 7, 2017 | In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF (End of File) check m... |
| CVE-2017-14173 | MEDIUM | 6.5 | 1.9% | Sep 7, 2017 | In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition... |
| CVE-2017-14172 | MEDIUM | 6.5 | 2.2% | Sep 7, 2017 | In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause ... |
| CVE-2017-5698 | MEDIUM | 4.4 | 0.3% | Sep 5, 2017 | Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions ... |
| CVE-2017-14159 | MEDIUM | 4.7 | 0.3% | Sep 5, 2017 | slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might all... |
| CVE-2017-14121 | MEDIUM | 5.5 | 1.1% | Sep 3, 2017 | The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer derefer... |
| CVE-2017-14107 | MEDIUM | 6.5 | 3.2% | Sep 1, 2017 | The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attacker... |
| CVE-2017-13672 | MEDIUM | 5.5 | 1.0% | Sep 1, 2017 | QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to c... |
| CVE-2017-1446 | MEDIUM | 5.4 | 0.7% | Aug 30, 2017 | IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2017-13769 | MEDIUM | 6.5 | 1.4% | Aug 30, 2017 | The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick through 7.0.6-10 allows an attacker to cause a den... |
| CVE-2017-13768 | MEDIUM | 6.5 | 2.1% | Aug 30, 2017 | Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick through 7.0.6-10 allows a... |
| CVE-2017-13760 | MEDIUM | 5.5 | 0.7% | Aug 29, 2017 | In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a. |
| CVE-2017-13756 | MEDIUM | 5.5 | 0.7% | Aug 29, 2017 | In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/v... |
| CVE-2017-13755 | MEDIUM | 5.5 | 0.7% | Aug 29, 2017 | In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in ... |
| CVE-2017-3151 | MEDIUM | 6.1 | 1.9% | Aug 29, 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the ... |
| CVE-2017-13734 | MEDIUM | 6.5 | 2.1% | Aug 29, 2017 | There is an illegal address access in the _nc_safe_strcat function in strings.c in ncurses 6.0 that will lead to a remot... |
| CVE-2017-13733 | MEDIUM | 6.5 | 2.7% | Aug 29, 2017 | There is an illegal address access in the fmt_entry function in progs/dump_entry.c in ncurses 6.0 that might lead to a r... |
| CVE-2017-13732 | MEDIUM | 6.5 | 2.9% | Aug 29, 2017 | There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a... |
| CVE-2017-13731 | MEDIUM | 6.5 | 2.9% | Aug 29, 2017 | There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead ... |
| CVE-2017-13730 | MEDIUM | 6.5 | 2.9% | Aug 29, 2017 | There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead... |
| CVE-2017-13729 | MEDIUM | 6.5 | 2.9% | Aug 29, 2017 | There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remot... |
| CVE-2017-10837 | MEDIUM | 6.1 | 0.9% | Aug 29, 2017 | Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web scr... |
| CVE-2017-12950 | MEDIUM | 6.5 | 5.1% | Aug 28, 2017 | The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL p... |
| CVE-2017-12877 | MEDIUM | 6.5 | 2.3% | Aug 28, 2017 | Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attacke... |
| CVE-2017-12876 | MEDIUM | 6.5 | 3.0% | Aug 28, 2017 | Heap-based buffer overflow in enhance.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of servi... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now