2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12734 | HIGH | 7.5 | 1.4% | Aug 30, 2017 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). An attacker with net... |
| CVE-2017-13752 | HIGH | 7.5 | 3.6% | Aug 29, 2017 | There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead t... |
| CVE-2017-13751 | HIGH | 7.5 | 3.6% | Aug 29, 2017 | There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to... |
| CVE-2017-13750 | HIGH | 7.5 | 3.7% | Aug 29, 2017 | There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that w... |
| CVE-2017-13749 | HIGH | 7.5 | 3.6% | Aug 29, 2017 | There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lea... |
| CVE-2017-13748 | HIGH | 7.5 | 4.7% | Aug 29, 2017 | There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will ... |
| CVE-2017-13747 | HIGH | 7.5 | 3.6% | Aug 29, 2017 | There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead t... |
| CVE-2017-13746 | HIGH | 7.5 | 4.0% | Aug 29, 2017 | There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that w... |
| CVE-2017-13728 | HIGH | 7.5 | 3.9% | Aug 29, 2017 | There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input wi... |
| CVE-2017-6594 | HIGH | 7.5 | 1.8% | Aug 28, 2017 | The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mech... |
| CVE-2017-12817 | HIGH | 7.5 | 0.9% | Aug 25, 2017 | In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted. |
| CVE-2017-9511 | HIGH | 7.5 | 3.2% | Aug 24, 2017 | The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to... |
| CVE-2017-9512 | HIGH | 7.5 | 2.0% | Aug 24, 2017 | The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote att... |
| CVE-2017-13146 | HIGH | 8.8 | 1.3% | Aug 23, 2017 | In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat.... |
| CVE-2017-10663 | HIGH | 7.8 | 0.4% | Aug 19, 2017 | The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and seg... |
| CVE-2017-10662 | HIGH | 7.8 | 0.5% | Aug 19, 2017 | The sanity_check_raw_super function in fs/f2fs/super.c in the Linux kernel before 4.11.1 does not validate the segment c... |
| CVE-2017-10661 | HIGH | 7 | 13.4% | Aug 19, 2017 | Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denia... |
| CVE-2017-11323 | HIGH | 7.8 | 2.8% | Aug 19, 2017 | Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a cr... |
| CVE-2017-11653 | HIGH | 7.8 | 0.4% | Aug 18, 2017 | Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain... |
| CVE-2017-11652 | HIGH | 8.4 | 0.4% | Aug 18, 2017 | Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users t... |
| CVE-2017-11185 | HIGH | 7.5 | 3.3% | Aug 18, 2017 | The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference... |
| CVE-2017-9454 | HIGH | 7.5 | 2.0% | Aug 18, 2017 | Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remo... |
| CVE-2017-12892 | HIGH | 7.8 | 3.3% | Aug 16, 2017 | Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein... |
| CVE-2017-7548 | HIGH | 7.5 | 3.5% | Aug 16, 2017 | PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated at... |
| CVE-2017-12864 | HIGH | 8.8 | 2.7% | Aug 15, 2017 | In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to inte... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now