2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12480Sandboxie installer 5071703 has a DLL Hijacking or Unsafe DLL Loading Vulnerability via a Trojan horse dwmapi.dll or pro...
CVE-2017-12586SLiMS 8 Akasia through 8.3.1 has an arbitrary file reading issue because of directory traversal in the url parameter to ...
CVE-2017-12585SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), ...
CVE-2017-12584HIGH8.8There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can b...
CVE-2017-12583DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php.
CVE-2017-12581GitHub Electron before 1.6.8 allows remote command execution because of a nodeIntegration bypass vulnerability. This als...
CVE-2017-12568Denial of Service vulnerability in Debut embedded httpd 1.20 in Brother DCP-J132W (and probably other DCP models) allows...
CVE-2017-12572Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x before 6.5.2, 6.4.x before 6.4.6, and 6.3.x befo...
CVE-2017-12566In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadMVGImage in coders/mvg.c, which allows...
CVE-2017-12565In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadOneJNGImage in coders/png.c, which all...
CVE-2017-12564In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows...
CVE-2017-12563In ImageMagick 7.0.6-2, a memory exhaustion vulnerability was found in the function ReadPSDImage in coders/psd.c, which ...
CVE-2017-9864An issue was discovered in SMA Solar Technology products. An attacker can change the plant time even when not authentica...
CVE-2017-9863An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits...
CVE-2017-9862An issue was discovered in SMA Solar Technology products. When signed into Sunny Explorer with a wrong password, it is p...
CVE-2017-9861An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication wi...
CVE-2017-9860An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network pr...
CVE-2017-9859An issue was discovered in SMA Solar Technology products. The inverters make use of a weak hashing algorithm to encrypt ...
CVE-2017-9858An issue was discovered in SMA Solar Technology products. By sending crafted packets to an inverter and observing the re...
CVE-2017-9857An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use aut...
CVE-2017-9856LOW3.4An issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypte...
CVE-2017-9855CRITICAL9.8An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers ...
CVE-2017-9854An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext p...
CVE-2017-9853An issue was discovered in SMA Solar Technology products. All inverters have a very weak password policy for the user an...
CVE-2017-9852An Incorrect Password Management issue was discovered in SMA Solar Technology products. Default passwords exist that are...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now