2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-0900 | — | — | 8.5% | Aug 31, 2017 | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service... |
| CVE-2017-0899 | — | — | 10.8% | Aug 31, 2017 | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape... |
| CVE-2017-14076 | — | — | 1.1% | Aug 31, 2017 | SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action. |
| CVE-2017-14070 | — | — | 0.6% | Aug 31, 2017 | Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF. |
| CVE-2017-14069 | — | — | 1.2% | Aug 31, 2017 | SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php. |
| CVE-2017-14064 | — | — | 9.4% | Aug 31, 2017 | Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call... |
| CVE-2017-14063 | — | — | 3.0% | Aug 31, 2017 | Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one ... |
| CVE-2017-14062 | CRITICAL | 9.8 | 4.0% | Aug 31, 2017 | Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause ... |
| CVE-2017-14061 | — | — | 2.4% | Aug 31, 2017 | Integer overflow in the _isBidi function in bidi.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of ... |
| CVE-2017-14060 | — | — | 1.6% | Aug 31, 2017 | In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is present in the ReadCUTImage function in coders/cut.c that c... |
| CVE-2017-14059 | — | — | 1.8% | Aug 31, 2017 | In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. Wh... |
| CVE-2017-14058 | — | — | 2.2% | Aug 31, 2017 | In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficie... |
| CVE-2017-14057 | — | — | 1.8% | Aug 31, 2017 | In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory co... |
| CVE-2017-14056 | — | — | 1.8% | Aug 31, 2017 | In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause h... |
| CVE-2017-14055 | — | — | 1.8% | Aug 31, 2017 | In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause ... |
| CVE-2017-14054 | — | — | 1.7% | Aug 31, 2017 | In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause... |
| CVE-2017-1450 | — | — | 0.8% | Aug 31, 2017 | IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect att... |
| CVE-2017-1449 | — | — | 0.6% | Aug 31, 2017 | IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect att... |
| CVE-2017-1447 | — | — | 0.5% | Aug 31, 2017 | IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2017-1444 | — | — | 0.6% | Aug 31, 2017 | IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2017-13708 | — | — | 11.7% | Aug 31, 2017 | Buffer overflow in the web server service in VX Search Enterprise 10.0.14 allows remote attackers to execute arbitrary c... |
| CVE-2017-11158 | — | — | 0.4% | Aug 31, 2017 | Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Win... |
| CVE-2017-14051 | — | — | 0.4% | Aug 31, 2017 | An integer overflow in the qla2x00_sysfs_write_optrom_ctl function in drivers/scsi/qla2xxx/qla_attr.c in the Linux kerne... |
| CVE-2017-14050 | — | — | 1.2% | Aug 31, 2017 | In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZI... |
| CVE-2017-14049 | — | — | 0.6% | Aug 31, 2017 | In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks vi... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now