2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14519 | — | — | 1.5% | Sep 17, 2017 | In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of G... |
| CVE-2017-14518 | — | — | 1.2% | Sep 17, 2017 | In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a c... |
| CVE-2017-14517 | — | — | 1.1% | Sep 17, 2017 | In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF doc... |
| CVE-2017-14515 | — | — | 1.2% | Sep 17, 2017 | Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause a denial of service ... |
| CVE-2017-14514 | — | — | 2.1% | Sep 17, 2017 | Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencrypted files via a craf... |
| CVE-2017-14513 | — | — | 1.8% | Sep 17, 2017 | Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file... |
| CVE-2017-14512 | — | — | 1.1% | Sep 17, 2017 | NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a differ... |
| CVE-2017-14511 | — | — | 1.4% | Sep 17, 2017 | An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the ... |
| CVE-2017-14510 | — | — | 1.4% | Sep 17, 2017 | An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community ... |
| CVE-2017-14509 | — | — | 5.8% | Sep 17, 2017 | An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community ... |
| CVE-2017-14508 | — | — | 2.6% | Sep 17, 2017 | An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community ... |
| CVE-2017-14505 | — | — | 1.5% | Sep 17, 2017 | DrawGetStrokeDashArray in wand/drawing-wand.c in ImageMagick 7.0.7-1 mishandles certain NULL arrays, which allows attack... |
| CVE-2017-14504 | — | — | 2.4% | Sep 17, 2017 | ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correct number of colors for the XV 332 format... |
| CVE-2017-14244 | CRITICAL | 9.8 | 17.1% | Sep 17, 2017 | An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows ... |
| CVE-2017-14243 | — | — | 14.8% | Sep 17, 2017 | An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers... |
| CVE-2017-14503 | — | — | 2.0% | Sep 17, 2017 | libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c whe... |
| CVE-2017-14502 | — | — | 3.4% | Sep 17, 2017 | read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names i... |
| CVE-2017-14501 | — | — | 2.1% | Sep 17, 2017 | An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when e... |
| CVE-2017-14500 | — | — | 3.1% | Sep 17, 2017 | Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsb... |
| CVE-2017-9328 | — | — | 7.4% | Sep 15, 2017 | Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads ... |
| CVE-2017-9805 | HIGH | 8.1 | 99.5% | Sep 15, 2017 | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a... |
| CVE-2017-0898 | — | — | 9.7% | Sep 15, 2017 | Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) w... |
| CVE-2017-2299 | — | — | 0.8% | Sep 15, 2017 | Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS tr... |
| CVE-2017-14498 | — | — | 1.3% | Sep 15, 2017 | SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the conte... |
| CVE-2017-14497 | HIGH | 7.8 | 0.6% | Sep 15, 2017 | The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now