2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-13755 | MEDIUM | 5.5 | 0.7% | Aug 29, 2017 | In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in ... |
| CVE-2017-0379 | — | — | 3.5% | Aug 29, 2017 | Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers t... |
| CVE-2017-1535 | — | — | 0.7% | Aug 29, 2017 | IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java... |
| CVE-2017-1485 | — | — | 0.5% | Aug 29, 2017 | IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java... |
| CVE-2017-1428 | — | — | 1.2% | Aug 29, 2017 | IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a vic... |
| CVE-2017-1427 | — | — | 1.0% | Aug 29, 2017 | IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java... |
| CVE-2017-1195 | — | — | 0.8% | Aug 29, 2017 | IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, us... |
| CVE-2017-3155 | — | — | 1.8% | Aug 29, 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting. |
| CVE-2017-3154 | — | — | 2.1% | Aug 29, 2017 | Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessiv... |
| CVE-2017-3153 | — | — | 2.0% | Aug 29, 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functio... |
| CVE-2017-3152 | — | — | 2.0% | Aug 29, 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionali... |
| CVE-2017-3151 | MEDIUM | 6.1 | 1.9% | Aug 29, 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the ... |
| CVE-2017-3150 | — | — | 2.0% | Aug 29, 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script. |
| CVE-2017-13673 | — | — | 3.0% | Aug 29, 2017 | The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used caus... |
| CVE-2017-12865 | CRITICAL | 9.8 | 5.5% | Aug 29, 2017 | Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of ser... |
| CVE-2017-12875 | — | — | 2.4% | Aug 29, 2017 | The WritePixelCachePixels function in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (CPU cons... |
| CVE-2017-12867 | — | — | 1.3% | Aug 29, 2017 | The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret... |
| CVE-2017-12856 | — | — | 0.8% | Aug 29, 2017 | Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote attackers to inject arbitrary web script or HTML v... |
| CVE-2017-12797 | — | — | 1.2% | Aug 29, 2017 | Integer overflow in the INT123_parse_new_id3 function in the ID3 parser in mpg123 before 1.25.5 on 32-bit platforms allo... |
| CVE-2017-12775 | — | — | 1.6% | Aug 29, 2017 | qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts. |
| CVE-2017-12763 | — | — | 3.9% | Aug 29, 2017 | An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privil... |
| CVE-2017-12422 | — | — | 1.6% | Aug 29, 2017 | NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote auth... |
| CVE-2017-11455 | — | — | 1.3% | Aug 29, 2017 | diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, ... |
| CVE-2017-10952 | — | — | 7.2% | Aug 29, 2017 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2... |
| CVE-2017-10951 | — | — | 3.9% | Aug 29, 2017 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.1... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now