2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-14319A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV spec...
CVE-2017-14318An issue was discovered in Xen 4.5.x through 4.9.x. The function `__gnttab_cache_flush` handles GNTTABOP_cache_flush gra...
CVE-2017-14317A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down...
CVE-2017-14316A parameter verification issue was discovered in Xen through 4.9.x. The function `alloc_heap_pages` allows callers to sp...
CVE-2017-14315In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large aud...
CVE-2017-14335On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT requ...
CVE-2017-14333The process_version_sections function in readelf.c in GNU Binutils 2.29 allows attackers to cause a denial of service (I...
CVE-2017-14326In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which al...
CVE-2017-14325In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function PersistPixelCache in magick/cache.c, w...
CVE-2017-14324In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMPCImage in coders/mpc.c, which al...
CVE-2017-14266HIGH7.8tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related...
CVE-2017-7735A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows at...
CVE-2017-7734A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauth...
CVE-2017-3133A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthor...
CVE-2017-3132A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthor...
CVE-2017-3131A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to exec...
CVE-2017-14314Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause ...
CVE-2017-14313The shibboleth_login_form function in shibboleth.php in the Shibboleth plugin before 1.8 for WordPress is prone to an XS...
CVE-2017-14312Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this f...
CVE-2017-1000249An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwri...
CVE-2017-14310STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...
CVE-2017-14309STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...
CVE-2017-14308STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...
CVE-2017-14307STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...
CVE-2017-14306STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now