2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-14619Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web scrip...
CVE-2017-14618Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject ...
CVE-2017-14617In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potentia...
CVE-2017-14616An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface...
CVE-2017-14615An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login en...
CVE-2017-14610bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privil...
CVE-2017-14609The server daemons in Kannel 1.5.0 and earlier create a PID file after dropping privileges to a non-root account, which ...
CVE-2017-14596In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username ...
CVE-2017-14595In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these artic...
CVE-2017-9804In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field an...
CVE-2017-9793The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library...
CVE-2017-14608In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c ...
CVE-2017-14607In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c. An a...
CVE-2017-12611In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in...
CVE-2017-9649A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Tran...
CVE-2017-9645An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmit...
CVE-2017-9607HIGH7The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure...
CVE-2017-7924An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L...
CVE-2017-14339The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is p...
CVE-2017-8772On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials ...
CVE-2017-8771On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials ...
CVE-2017-8770There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesys...
CVE-2017-14604MEDIUM6.5GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrate...
CVE-2017-12168MEDIUM6The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM gues...
CVE-2017-12883Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 al...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now