2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14619 | — | — | 2.2% | Sep 20, 2017 | Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web scrip... |
| CVE-2017-14618 | — | — | 2.4% | Sep 20, 2017 | Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject ... |
| CVE-2017-14617 | — | — | 0.9% | Sep 20, 2017 | In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potentia... |
| CVE-2017-14616 | — | — | 1.6% | Sep 20, 2017 | An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface... |
| CVE-2017-14615 | — | — | 0.9% | Sep 20, 2017 | An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login en... |
| CVE-2017-14610 | — | — | 0.3% | Sep 20, 2017 | bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privil... |
| CVE-2017-14609 | — | — | 0.4% | Sep 20, 2017 | The server daemons in Kannel 1.5.0 and earlier create a PID file after dropping privileges to a non-root account, which ... |
| CVE-2017-14596 | — | — | 6.3% | Sep 20, 2017 | In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username ... |
| CVE-2017-14595 | — | — | 1.8% | Sep 20, 2017 | In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these artic... |
| CVE-2017-9804 | — | — | 9.5% | Sep 20, 2017 | In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field an... |
| CVE-2017-9793 | — | — | 7.3% | Sep 20, 2017 | The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library... |
| CVE-2017-14608 | — | — | 2.1% | Sep 20, 2017 | In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c ... |
| CVE-2017-14607 | — | — | 2.3% | Sep 20, 2017 | In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c. An a... |
| CVE-2017-12611 | — | — | 88.0% | Sep 20, 2017 | In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in... |
| CVE-2017-9649 | — | — | 0.5% | Sep 20, 2017 | A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Tran... |
| CVE-2017-9645 | — | — | 0.2% | Sep 20, 2017 | An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmit... |
| CVE-2017-9607 | HIGH | 7 | 0.8% | Sep 20, 2017 | The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure... |
| CVE-2017-7924 | — | — | 22.2% | Sep 20, 2017 | An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L... |
| CVE-2017-14339 | — | — | 2.5% | Sep 20, 2017 | The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is p... |
| CVE-2017-8772 | — | — | 1.4% | Sep 20, 2017 | On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials ... |
| CVE-2017-8771 | — | — | 1.4% | Sep 20, 2017 | On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials ... |
| CVE-2017-8770 | — | — | 10.3% | Sep 20, 2017 | There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesys... |
| CVE-2017-14604 | MEDIUM | 6.5 | 2.5% | Sep 20, 2017 | GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrate... |
| CVE-2017-12168 | MEDIUM | 6 | 0.4% | Sep 20, 2017 | The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM gues... |
| CVE-2017-12883 | — | — | 5.9% | Sep 19, 2017 | Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 al... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now