2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-13060 | — | — | 1.2% | Aug 22, 2017 | In ImageMagick 7.0.6-5, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows... |
| CVE-2017-13059 | — | — | 1.5% | Aug 22, 2017 | In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function WriteOneJNGImage in coders/png.c, which al... |
| CVE-2017-13058 | — | — | 1.5% | Aug 22, 2017 | In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function WritePCXImage in coders/pcx.c, which allow... |
| CVE-2017-8037 | — | — | 1.4% | Aug 21, 2017 | In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 a... |
| CVE-2017-6329 | — | — | 0.6% | Aug 21, 2017 | Symantec VIP Access for Desktop prior to 2.2.4 can be susceptible to a DLL Pre-Loading vulnerability. These types of iss... |
| CVE-2017-7424 | — | — | 1.8% | Aug 21, 2017 | A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.... |
| CVE-2017-7423 | — | — | 0.8% | Aug 21, 2017 | A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise S... |
| CVE-2017-7422 | — | — | 1.0% | Aug 21, 2017 | Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Develop... |
| CVE-2017-7421 | — | — | 1.3% | Aug 21, 2017 | Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Admin... |
| CVE-2017-7420 | — | — | 2.4% | Aug 21, 2017 | An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Ent... |
| CVE-2017-5187 | — | — | 0.8% | Aug 21, 2017 | A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) i... |
| CVE-2017-12984 | — | — | 1.9% | Aug 21, 2017 | PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php. |
| CVE-2017-12983 | — | — | 2.4% | Aug 21, 2017 | Heap-based buffer overflow in the ReadSFWImage function in coders/sfw.c in ImageMagick 7.0.6-8 allows remote attackers t... |
| CVE-2017-12982 | MEDIUM | 5.5 | 2.9% | Aug 21, 2017 | The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCou... |
| CVE-2017-12981 | — | — | 1.2% | Aug 21, 2017 | NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action. |
| CVE-2017-12980 | — | — | 1.4% | Aug 21, 2017 | DokuWiki through 2017-02-19c has stored XSS when rendering a malicious RSS or Atom feed, in /inc/parser/xhtml.php. An at... |
| CVE-2017-12979 | — | — | 1.4% | Aug 21, 2017 | DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language name in a code element, in /inc/parser/x... |
| CVE-2017-12978 | — | — | 0.8% | Aug 21, 2017 | lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user. |
| CVE-2017-12784 | — | — | 2.3% | Aug 21, 2017 | In Youngzsoft CCFile (aka CC File Transfer) 3.6, by sending a crafted HTTP request, it is possible for a malicious user ... |
| CVE-2017-12977 | — | — | 1.6% | Aug 21, 2017 | The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection v... |
| CVE-2017-11366 | — | — | 7.8% | Aug 21, 2017 | components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because sh... |
| CVE-2017-1000124 | — | — | — | Aug 21, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11366. Reason: This candidate is a reservation ... |
| CVE-2017-1000216 | — | — | — | Aug 21, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11104. Reason: This candidate is a reservation ... |
| CVE-2017-1000205 | — | — | — | Aug 21, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-9091. Reason: This candidate is a reservation ... |
| CVE-2017-1000202 | — | — | — | Aug 21, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-12933. Reason: This candidate is a reservation ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now