2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14680 | — | — | 4.3% | Sep 21, 2017 | ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a P... |
| CVE-2017-9283 | — | — | 1.2% | Sep 21, 2017 | An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5. The feasibility of leveraging this v... |
| CVE-2017-9282 | — | — | 1.2% | Sep 21, 2017 | An integer overflow (CWE-190) led to an out-of-bounds write (CWE-787) on a heap-allocated area, leading to heap corrupti... |
| CVE-2017-9281 | — | — | 1.0% | Sep 21, 2017 | An integer overflow (CWE-190) potentially causing an out-of-bounds read (CWE-125) vulnerability in Micro Focus VisiBroke... |
| CVE-2017-7549 | — | — | 0.3% | Sep 21, 2017 | A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Ha... |
| CVE-2017-7544 | — | — | 3.3% | Sep 21, 2017 | libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in l... |
| CVE-2017-12170 | — | — | 1.5% | Sep 21, 2017 | Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the origina... |
| CVE-2017-14652 | — | — | 1.7% | Sep 21, 2017 | SQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin before 4.5.8 for MyBB allows an unaut... |
| CVE-2017-14651 | MEDIUM | 4.8 | 3.8% | Sep 21, 2017 | WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or ... |
| CVE-2017-14650 | — | — | 4.0% | Sep 21, 2017 | A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilize... |
| CVE-2017-14649 | — | — | 1.3% | Sep 21, 2017 | ReadOneJNGImage in coders/png.c in GraphicsMagick version 1.3.26 does not properly validate JNG data, leading to a denia... |
| CVE-2017-14648 | CRITICAL | 9.8 | 3.4% | Sep 21, 2017 | A global buffer overflow was discovered in the iteration_loop function in loop.c in BladeEnc version 0.94.2. The vulnera... |
| CVE-2017-14647 | — | — | 2.0% | Sep 21, 2017 | A heap-based buffer overflow was discovered in AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.... |
| CVE-2017-14646 | — | — | 2.2% | Sep 21, 2017 | The AP4_AvccAtom and AP4_HvccAtom classes in Bento4 version 1.5.0-617 do not properly validate data sizes, leading to a ... |
| CVE-2017-14645 | — | — | 1.2% | Sep 21, 2017 | A heap-based buffer over-read was discovered in AP4_BitStream::ReadBytes in Codecs/Ap4BitStream.cpp in Bento4 version 1.... |
| CVE-2017-14644 | — | — | 2.4% | Sep 21, 2017 | A heap-based buffer overflow was discovered in the AP4_HdlrAtom class in Bento4 1.5.0-617. The vulnerability causes an o... |
| CVE-2017-14643 | — | — | 1.6% | Sep 21, 2017 | The AP4_HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leadin... |
| CVE-2017-14642 | — | — | 1.7% | Sep 21, 2017 | A NULL pointer dereference was discovered in the AP4_HdlrAtom class in Bento4 version 1.5.0-617. The vulnerability cause... |
| CVE-2017-14641 | — | — | 1.7% | Sep 21, 2017 | A NULL pointer dereference was discovered in the AP4_DataAtom class in MetaData/Ap4MetaData.cpp in Bento4 version 1.5.0-... |
| CVE-2017-14640 | — | — | 1.7% | Sep 21, 2017 | A NULL pointer dereference was discovered in AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp in Bento4 ver... |
| CVE-2017-14639 | — | — | 1.7% | Sep 21, 2017 | AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect character data types, wh... |
| CVE-2017-14638 | — | — | 1.6% | Sep 21, 2017 | AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp in Bento4 version 1.5.0-617 has missing NULL checks, le... |
| CVE-2017-14321 | — | — | 0.6% | Sep 21, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative interface in Mirasvit Helpdesk MX before 1.5.3... |
| CVE-2017-14320 | — | — | 1.4% | Sep 21, 2017 | Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter... |
| CVE-2017-12930 | — | — | 3.1% | Sep 21, 2017 | SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now