2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14023 | MEDIUM | 4.9 | 3.7% | Nov 6, 2017 | An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13... |
| CVE-2017-14016 | — | — | 16.0% | Nov 6, 2017 | A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati... |
| CVE-2017-12719 | — | — | 3.1% | Nov 6, 2017 | An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A remote a... |
| CVE-2017-15306 | — | — | 0.4% | Nov 6, 2017 | The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the Linux kernel before 4.13.11 allows local ... |
| CVE-2017-7425 | HIGH | 7.6 | 0.9% | Nov 6, 2017 | Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 and 3.0.3.2. |
| CVE-2017-16001 | — | — | 0.9% | Nov 6, 2017 | In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently su... |
| CVE-2017-15672 | — | — | 2.0% | Nov 6, 2017 | The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to... |
| CVE-2017-11177 | — | — | 1.0% | Nov 6, 2017 | TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory. |
| CVE-2017-16570 | — | — | 2.2% | Nov 6, 2017 | KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureL... |
| CVE-2017-16569 | — | — | 0.5% | Nov 6, 2017 | An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index... |
| CVE-2017-16565 | — | — | 0.5% | Nov 6, 2017 | Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authentica... |
| CVE-2017-16564 | — | — | 0.6% | Nov 6, 2017 | Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote ... |
| CVE-2017-16563 | — | — | 0.4% | Nov 6, 2017 | Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to... |
| CVE-2017-16524 | — | — | 30.3% | Nov 6, 2017 | Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_u... |
| CVE-2017-15039 | — | — | 0.5% | Nov 6, 2017 | Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.... |
| CVE-2017-16548 | CRITICAL | 9.8 | 5.2% | Nov 6, 2017 | The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character... |
| CVE-2017-16547 | — | — | 2.3% | Nov 6, 2017 | The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are asso... |
| CVE-2017-16546 | HIGH | 8.8 | 2.2% | Nov 5, 2017 | The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG ... |
| CVE-2017-16545 | — | — | 2.2% | Nov 5, 2017 | The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which ... |
| CVE-2017-16543 | — | — | 5.6% | Nov 5, 2017 | Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated ... |
| CVE-2017-16542 | — | — | 5.5% | Nov 5, 2017 | Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name param... |
| CVE-2017-16540 | — | — | 1.3% | Nov 4, 2017 | OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for ... |
| CVE-2017-16541 | MEDIUM | 6.5 | 3.7% | Nov 4, 2017 | Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discove... |
| CVE-2017-16539 | MEDIUM | 5.9 | 1.8% | Nov 4, 2017 | The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, ... |
| CVE-2017-16538 | — | — | 0.4% | Nov 4, 2017 | drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of servi... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now