2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12692The ReadVIFFImage function in coders/viff.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service ...
CVE-2017-12691The ReadOneLayer function in coders/xcf.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (m...
CVE-2017-12423NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on other Storage Virtua...
CVE-2017-12421NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbitrary code on the sto...
CVE-2017-14107MEDIUM6.5The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attacker...
CVE-2017-14105HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, be...
CVE-2017-14106The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of se...
CVE-2017-10851Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an atta...
CVE-2017-10850HIGH7.8Untrusted search path vulnerability in Installers of ART EX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271,...
CVE-2017-10849Untrusted search path vulnerability in Self-extracting document generated by DocuWorks 8.0.7 and earlier allows an attac...
CVE-2017-10848Untrusted search path vulnerability in Installers for DocuWorks 8.0.7 and earlier and DocuWorks Viewer Light published i...
CVE-2017-10829Untrusted search path vulnerability in Remote Support Tool (Enkaku Support Tool) All versions distributed through the we...
CVE-2017-3898A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) ...
CVE-2017-3897A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior ...
CVE-2017-14103The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image poi...
CVE-2017-13711HIGH7.5Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to c...
CVE-2017-13674Symantec ProxyClient 3.4 for Windows is susceptible to a privilege escalation vulnerability. A malicious local Windows u...
CVE-2017-13672MEDIUM5.5QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to c...
CVE-2017-12870SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leve...
CVE-2017-12869The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restr...
CVE-2017-12868The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP bef...
CVE-2017-14102MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local ...
CVE-2017-7855In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" paramet...
CVE-2017-0902RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force ...
CVE-2017-0901RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potenti...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now