2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-4905MEDIUM5.5VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi...
CVE-2017-9060MEDIUM5.5Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local ...
CVE-2017-6512MEDIUM5.9Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to ...
CVE-2017-9287MEDIUM6.5servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access t...
CVE-2017-9249MEDIUM5.4Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web scr...
CVE-2017-5646MEDIUM6.8For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate ...
CVE-2017-8537MEDIUM5.5The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve...
CVE-2017-8536MEDIUM5.5The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve...
CVE-2017-8535MEDIUM5.5The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve...
CVE-2017-9037MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remo...
CVE-2017-9032MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remo...
CVE-2017-2801MEDIUM6.5A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string compariso...
CVE-2017-9216MEDIUM6.5libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_hu...
CVE-2017-8379MEDIUM6.5Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged u...
CVE-2017-9144MEDIUM6.5In ImageMagick 7.0.5-5, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c.
CVE-2017-9143MEDIUM6.5In ImageMagick 7.0.5-5, the ReadARTImage function in coders/art.c allows attackers to cause a denial of service (memory ...
CVE-2017-9142MEDIUM6.5In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/bl...
CVE-2017-9141MEDIUM6.5In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function ...
CVE-2017-9117MEDIUM4In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeig...
CVE-2017-7475MEDIUM5.5Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph result...
CVE-2017-8769MEDIUM4.6Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Document...
CVE-2017-4015MEDIUM4.5Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated...
CVE-2017-8943MEDIUM5.9The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle ...
CVE-2017-8939MEDIUM5.9The Warner Bros. ellentube app 3.1.1 through 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which al...
CVE-2017-8938MEDIUM5.9The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now