2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12135Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain pr...
CVE-2017-12134The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt bloc...
CVE-2017-13666An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x...
CVE-2017-13658In ImageMagick before 6.9.9-3 and 7.x before 7.0.6-3, there is a missing NULL check in the ReadMATImage function in code...
CVE-2017-0805A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4....
CVE-2017-13649UnrealIRCd 4.0.13 and earlier creates a PID file after dropping privileges to a non-root account, which might allow loca...
CVE-2017-13648In GraphicsMagick 1.3.26, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c.
CVE-2017-12847Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might all...
CVE-2017-9506The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before ...
CVE-2017-13147In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c whe...
CVE-2017-11357CRITICAL9.8Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a...
CVE-2017-11317CRITICAL9.8Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload...
CVE-2017-12971Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or...
CVE-2017-12970Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authenticati...
CVE-2017-12965Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa...
CVE-2017-12809MEDIUM6.5QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privilege...
CVE-2017-11159Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windo...
CVE-2017-13138DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers...
CVE-2017-13137CRITICAL9.8The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.
CVE-2017-12904Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 thr...
CVE-2017-12858CRITICAL9.8Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecifie...
CVE-2017-12844Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated do...
CVE-2017-12791Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7....
CVE-2017-11610The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem...
CVE-2017-13146HIGH8.8In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat....

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now