2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-4905 | MEDIUM | 5.5 | 1.2% | Jun 7, 2017 | VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi... |
| CVE-2017-9060 | MEDIUM | 5.5 | 0.4% | Jun 1, 2017 | Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local ... |
| CVE-2017-6512 | MEDIUM | 5.9 | 2.4% | Jun 1, 2017 | Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to ... |
| CVE-2017-9287 | MEDIUM | 6.5 | 7.1% | May 29, 2017 | servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access t... |
| CVE-2017-9249 | MEDIUM | 5.4 | 0.7% | May 28, 2017 | Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web scr... |
| CVE-2017-5646 | MEDIUM | 6.8 | 0.8% | May 26, 2017 | For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate ... |
| CVE-2017-8537 | MEDIUM | 5.5 | 16.8% | May 26, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve... |
| CVE-2017-8536 | MEDIUM | 5.5 | 16.8% | May 26, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve... |
| CVE-2017-8535 | MEDIUM | 5.5 | 16.8% | May 26, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve... |
| CVE-2017-9037 | MEDIUM | 6.1 | 2.5% | May 26, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remo... |
| CVE-2017-9032 | MEDIUM | 6.1 | 2.5% | May 26, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remo... |
| CVE-2017-2801 | MEDIUM | 6.5 | 1.3% | May 24, 2017 | A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string compariso... |
| CVE-2017-9216 | MEDIUM | 6.5 | 3.5% | May 24, 2017 | libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_hu... |
| CVE-2017-8379 | MEDIUM | 6.5 | 0.4% | May 23, 2017 | Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged u... |
| CVE-2017-9144 | MEDIUM | 6.5 | 1.9% | May 22, 2017 | In ImageMagick 7.0.5-5, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. |
| CVE-2017-9143 | MEDIUM | 6.5 | 2.1% | May 22, 2017 | In ImageMagick 7.0.5-5, the ReadARTImage function in coders/art.c allows attackers to cause a denial of service (memory ... |
| CVE-2017-9142 | MEDIUM | 6.5 | 2.2% | May 22, 2017 | In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/bl... |
| CVE-2017-9141 | MEDIUM | 6.5 | 2.2% | May 22, 2017 | In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function ... |
| CVE-2017-9117 | MEDIUM | 4 | 2.2% | May 21, 2017 | In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeig... |
| CVE-2017-7475 | MEDIUM | 5.5 | 1.8% | May 19, 2017 | Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph result... |
| CVE-2017-8769 | MEDIUM | 4.6 | 0.2% | May 18, 2017 | Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Document... |
| CVE-2017-4015 | MEDIUM | 4.5 | 1.1% | May 17, 2017 | Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated... |
| CVE-2017-8943 | MEDIUM | 5.9 | 0.6% | May 15, 2017 | The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle ... |
| CVE-2017-8939 | MEDIUM | 5.9 | 0.6% | May 15, 2017 | The Warner Bros. ellentube app 3.1.1 through 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which al... |
| CVE-2017-8938 | MEDIUM | 5.9 | 0.7% | May 15, 2017 | The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now