2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12838 | — | — | 0.6% | Sep 7, 2017 | Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of ... |
| CVE-2017-12794 | — | — | 23.6% | Sep 7, 2017 | In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for... |
| CVE-2017-12416 | — | — | 1.2% | Sep 7, 2017 | Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Netwo... |
| CVE-2017-12133 | — | — | 2.4% | Sep 7, 2017 | Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6)... |
| CVE-2017-11567 | — | — | 4.1% | Sep 7, 2017 | Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the ... |
| CVE-2017-14175 | MEDIUM | 6.5 | 2.1% | Sep 7, 2017 | In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of File) check might caus... |
| CVE-2017-14174 | MEDIUM | 6.5 | 2.2% | Sep 7, 2017 | In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF (End of File) check m... |
| CVE-2017-14173 | MEDIUM | 6.5 | 1.9% | Sep 7, 2017 | In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition... |
| CVE-2017-14172 | MEDIUM | 6.5 | 2.2% | Sep 7, 2017 | In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause ... |
| CVE-2017-14171 | — | — | 1.8% | Sep 7, 2017 | In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) ch... |
| CVE-2017-14170 | — | — | 1.8% | Sep 7, 2017 | In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File... |
| CVE-2017-14169 | — | — | 2.6% | Sep 7, 2017 | In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might o... |
| CVE-2017-14166 | — | — | 3.3% | Sep 6, 2017 | libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and applicat... |
| CVE-2017-14165 | — | — | 2.3% | Sep 6, 2017 | The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has an issue where memory allocation is excessive bec... |
| CVE-2017-14164 | HIGH | 8.8 | 5.4% | Sep 6, 2017 | A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability ca... |
| CVE-2017-12476 | — | — | 1.1% | Sep 6, 2017 | The AP4_AvccAtom::InspectFields function in Core/Ap4AvccAtom.cpp in Bento4 mp4dump before 1.5.0-616 allows remote attack... |
| CVE-2017-12475 | — | — | 1.1% | Sep 6, 2017 | The AP4_Processor::Process function in Core/Ap4Processor.cpp in Bento4 mp4encrypt before 1.5.0-616 allows remote attacke... |
| CVE-2017-12474 | — | — | 1.1% | Sep 6, 2017 | The AP4_AtomSampleTable::GetSample function in Core/Ap4AtomSampleTable.cpp in Bento4 mp42ts before 1.5.0-616 allows remo... |
| CVE-2017-1491 | — | — | 1.3% | Sep 5, 2017 | IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which ... |
| CVE-2017-1458 | — | — | 2.5% | Sep 5, 2017 | IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. ... |
| CVE-2017-1457 | — | — | 1.3% | Sep 5, 2017 | IBM QRadar Network Security 5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2017-1130 | — | — | 29.2% | Sep 5, 2017 | IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it woul... |
| CVE-2017-1129 | — | — | 30.1% | Sep 5, 2017 | IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul... |
| CVE-2017-1097 | — | — | 0.6% | Sep 5, 2017 | IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site request forgery ... |
| CVE-2017-5716 | — | — | — | Sep 5, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-12865. Reason: This candidate is a reservation... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now