2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-14549STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, re...
CVE-2017-14548STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, re...
CVE-2017-14547STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...
CVE-2017-14546STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...
CVE-2017-14545STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...
CVE-2017-14544STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...
CVE-2017-14543STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...
CVE-2017-14542STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .epub file, re...
CVE-2017-14541XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other...
CVE-2017-14540IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a cra...
CVE-2017-14539IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a cra...
CVE-2017-14538XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a cr...
CVE-2017-0380The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x...
CVE-2017-9798HIGH7.5Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user...
CVE-2017-14534Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.
CVE-2017-12157In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
CVE-2017-12156Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
CVE-2017-9333OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/co...
CVE-2017-14533ImageMagick 7.0.6-6 has a memory leak in ReadMATImage in coders/mat.c.
CVE-2017-14532ImageMagick 7.0.7-0 has a NULL Pointer Dereference in TIFFIgnoreTags in coders/tiff.c.
CVE-2017-14531ImageMagick 7.0.7-0 has a memory exhaustion issue in ReadSUNImage in coders/sun.c.
CVE-2017-14530HIGH8WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=...
CVE-2017-14529The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GN...
CVE-2017-14528MEDIUM6.5The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFF...
CVE-2017-14520In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a poten...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now