2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12937The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.
CVE-2017-12936The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with e...
CVE-2017-12935The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid me...
CVE-2017-12934ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free whi...
CVE-2017-12933The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x...
CVE-2017-12932ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free w...
CVE-2017-12927A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
CVE-2017-6790A vulnerability in the Session Initiation Protocol (SIP) on the Cisco TelePresence Video Communication Server (VCS) coul...
CVE-2017-6788The WebLaunch functionality of Cisco AnyConnect Secure Mobility Client Software contains a vulnerability that could allo...
CVE-2017-6786A vulnerability in Cisco Elastic Services Controller could allow an authenticated, local, unprivileged attacker to acces...
CVE-2017-6785A vulnerability in configuration modification permissions validation for Cisco Unified Communications Manager could allo...
CVE-2017-6784A vulnerability in the web interface of the Cisco RV340, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an u...
CVE-2017-6783A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content ...
CVE-2017-6782A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote a...
CVE-2017-6781A vulnerability in the management of shell user accounts for Cisco Policy Suite (CPS) Software for CPS appliances could ...
CVE-2017-6778A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow ...
CVE-2017-6777A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an authenticated, remote ...
CVE-2017-6776A vulnerability in the web framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote a...
CVE-2017-6775A vulnerability in the CLI of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating syste...
CVE-2017-6774A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could all...
CVE-2017-6773A vulnerability in the CLI of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating syste...
CVE-2017-6772A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensiti...
CVE-2017-6771A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, rem...
CVE-2017-6768A vulnerability in the build procedure for certain executable system files installed at boot time on Cisco Application P...
CVE-2017-6767A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attack...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now