2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12692 | — | — | 2.9% | Sep 1, 2017 | The ReadVIFFImage function in coders/viff.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service ... |
| CVE-2017-12691 | — | — | 1.9% | Sep 1, 2017 | The ReadOneLayer function in coders/xcf.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (m... |
| CVE-2017-12423 | — | — | 1.0% | Sep 1, 2017 | NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on other Storage Virtua... |
| CVE-2017-12421 | — | — | 1.8% | Sep 1, 2017 | NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbitrary code on the sto... |
| CVE-2017-14107 | MEDIUM | 6.5 | 3.2% | Sep 1, 2017 | The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attacker... |
| CVE-2017-14105 | — | — | 1.3% | Sep 1, 2017 | HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, be... |
| CVE-2017-14106 | — | — | 0.4% | Sep 1, 2017 | The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of se... |
| CVE-2017-10851 | — | — | 1.1% | Sep 1, 2017 | Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an atta... |
| CVE-2017-10850 | HIGH | 7.8 | 1.0% | Sep 1, 2017 | Untrusted search path vulnerability in Installers of ART EX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271,... |
| CVE-2017-10849 | — | — | 1.1% | Sep 1, 2017 | Untrusted search path vulnerability in Self-extracting document generated by DocuWorks 8.0.7 and earlier allows an attac... |
| CVE-2017-10848 | — | — | 1.1% | Sep 1, 2017 | Untrusted search path vulnerability in Installers for DocuWorks 8.0.7 and earlier and DocuWorks Viewer Light published i... |
| CVE-2017-10829 | — | — | 1.2% | Sep 1, 2017 | Untrusted search path vulnerability in Remote Support Tool (Enkaku Support Tool) All versions distributed through the we... |
| CVE-2017-3898 | — | — | 3.2% | Sep 1, 2017 | A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) ... |
| CVE-2017-3897 | — | — | 11.7% | Sep 1, 2017 | A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior ... |
| CVE-2017-14103 | — | — | 30.2% | Sep 1, 2017 | The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image poi... |
| CVE-2017-13711 | HIGH | 7.5 | 3.8% | Sep 1, 2017 | Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to c... |
| CVE-2017-13674 | — | — | 0.4% | Sep 1, 2017 | Symantec ProxyClient 3.4 for Windows is susceptible to a privilege escalation vulnerability. A malicious local Windows u... |
| CVE-2017-13672 | MEDIUM | 5.5 | 1.0% | Sep 1, 2017 | QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to c... |
| CVE-2017-12870 | — | — | 0.9% | Sep 1, 2017 | SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leve... |
| CVE-2017-12869 | — | — | 2.3% | Sep 1, 2017 | The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restr... |
| CVE-2017-12868 | — | — | 2.1% | Sep 1, 2017 | The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP bef... |
| CVE-2017-14102 | — | — | 0.4% | Sep 1, 2017 | MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local ... |
| CVE-2017-7855 | — | — | 2.0% | Aug 31, 2017 | In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" paramet... |
| CVE-2017-0902 | — | — | 4.8% | Aug 31, 2017 | RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force ... |
| CVE-2017-0901 | — | — | 29.4% | Aug 31, 2017 | RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potenti... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now