2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-13145MEDIUM6.5In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly valida...
CVE-2017-13144In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the ima...
CVE-2017-13143In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data,...
CVE-2017-13142In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, a crafted PNG file could trigger a crash because there was an insu...
CVE-2017-13141In ImageMagick before 6.9.9-4 and 7.x before 7.0.6-4, a crafted file could trigger a memory leak in ReadOnePNGImage in c...
CVE-2017-13140In ImageMagick before 6.9.9-1 and 7.x before 7.0.6-2, the ReadOnePNGImage function in coders/png.c allows remote attacke...
CVE-2017-13139CRITICAL9.8In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds ...
CVE-2017-13134In ImageMagick 7.0.6-6 and GraphicsMagick 1.3.26, a heap-based buffer over-read was found in the function SFWScan in cod...
CVE-2017-13133In ImageMagick 7.0.6-8, the load_level function in coders/xcf.c lacks offset validation, which allows attackers to cause...
CVE-2017-13132In ImageMagick 7.0.6-8, the WritePDFImage function in coders/pdf.c operates on an incorrect data structure in the "dump ...
CVE-2017-13131In ImageMagick 7.0.6-8, a memory leak vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allo...
CVE-2017-13130mcmnm in BMC Patrol allows local users to gain privileges via a crafted libmcmclnx.so file in the current working direct...
CVE-2017-1422IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications whi...
CVE-2017-5208Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service ...
CVE-2017-12787A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through N...
CVE-2017-12786Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW40...
CVE-2017-12785The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on Novi...
CVE-2017-7557dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
CVE-2017-12843Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) S...
CVE-2017-13066GraphicsMagick 1.3.26 has a memory leak vulnerability in the function CloneImage in magick/image.c.
CVE-2017-13065GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.
CVE-2017-13064GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:...
CVE-2017-13063GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:...
CVE-2017-13062In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function formatIPTC in coders/meta.c, which allows ...
CVE-2017-13061In ImageMagick 7.0.6-5, a length-validation vulnerability was found in the function ReadPSDLayersInternal in coders/psd....

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now