2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12135 | — | — | 0.5% | Aug 24, 2017 | Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain pr... |
| CVE-2017-12134 | — | — | 0.5% | Aug 24, 2017 | The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt bloc... |
| CVE-2017-13666 | — | — | 0.4% | Aug 24, 2017 | An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x... |
| CVE-2017-13658 | — | — | 1.3% | Aug 24, 2017 | In ImageMagick before 6.9.9-3 and 7.x before 7.0.6-3, there is a missing NULL check in the ReadMATImage function in code... |
| CVE-2017-0805 | — | — | 0.4% | Aug 24, 2017 | A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.... |
| CVE-2017-13649 | — | — | 0.3% | Aug 23, 2017 | UnrealIRCd 4.0.13 and earlier creates a PID file after dropping privileges to a non-root account, which might allow loca... |
| CVE-2017-13648 | — | — | 1.4% | Aug 23, 2017 | In GraphicsMagick 1.3.26, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c. |
| CVE-2017-12847 | — | — | 0.8% | Aug 23, 2017 | Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might all... |
| CVE-2017-9506 | — | — | 71.6% | Aug 23, 2017 | The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before ... |
| CVE-2017-13147 | — | — | 1.5% | Aug 23, 2017 | In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c whe... |
| CVE-2017-11357 | CRITICAL | 9.8 | 75.7% | Aug 23, 2017 | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a... |
| CVE-2017-11317 | CRITICAL | 9.8 | 83.5% | Aug 23, 2017 | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload... |
| CVE-2017-12971 | — | — | 2.6% | Aug 23, 2017 | Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or... |
| CVE-2017-12970 | — | — | 2.2% | Aug 23, 2017 | Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authenticati... |
| CVE-2017-12965 | — | — | 15.7% | Aug 23, 2017 | Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa... |
| CVE-2017-12809 | MEDIUM | 6.5 | 0.4% | Aug 23, 2017 | QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privilege... |
| CVE-2017-11159 | — | — | 0.4% | Aug 23, 2017 | Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windo... |
| CVE-2017-13138 | — | — | 1.2% | Aug 23, 2017 | DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers... |
| CVE-2017-13137 | CRITICAL | 9.8 | 2.3% | Aug 23, 2017 | The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php. |
| CVE-2017-12904 | — | — | 6.4% | Aug 23, 2017 | Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 thr... |
| CVE-2017-12858 | CRITICAL | 9.8 | 3.7% | Aug 23, 2017 | Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecifie... |
| CVE-2017-12844 | — | — | 0.8% | Aug 23, 2017 | Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated do... |
| CVE-2017-12791 | — | — | 4.6% | Aug 23, 2017 | Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.... |
| CVE-2017-11610 | — | — | 87.5% | Aug 23, 2017 | The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem... |
| CVE-2017-13146 | HIGH | 8.8 | 1.3% | Aug 23, 2017 | In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat.... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now