2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12145 | — | — | 1.1% | Aug 2, 2017 | In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attac... |
| CVE-2017-12144 | — | — | 1.0% | Aug 2, 2017 | In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause... |
| CVE-2017-12143 | — | — | 1.0% | Aug 2, 2017 | In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which all... |
| CVE-2017-12142 | — | — | 1.0% | Aug 2, 2017 | In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attack... |
| CVE-2017-12141 | — | — | 1.1% | Aug 2, 2017 | In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allo... |
| CVE-2017-12140 | — | — | 2.2% | Aug 2, 2017 | The ReadDCMImage function in coders\dcm.c in ImageMagick 7.0.6-1 has an integer signedness error leading to excessive me... |
| CVE-2017-12139 | — | — | 0.8% | Aug 2, 2017 | XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php... |
| CVE-2017-12138 | — | — | 3.4% | Aug 2, 2017 | XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter. |
| CVE-2017-8663 | — | — | 20.1% | Aug 1, 2017 | Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Mic... |
| CVE-2017-8572 | — | — | 12.6% | Aug 1, 2017 | Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Mic... |
| CVE-2017-8571 | — | — | 5.8% | Aug 1, 2017 | Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Mic... |
| CVE-2017-1500 | — | — | 0.8% | Aug 1, 2017 | A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of ... |
| CVE-2017-4923 | — | — | 1.9% | Aug 1, 2017 | VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plain... |
| CVE-2017-4922 | — | — | 1.3% | Aug 1, 2017 | VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script u... |
| CVE-2017-4921 | — | — | 1.7% | Aug 1, 2017 | VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_... |
| CVE-2017-12132 | — | — | 1.9% | Aug 1, 2017 | The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will ... |
| CVE-2017-12062 | — | — | 3.9% | Aug 1, 2017 | An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized be... |
| CVE-2017-12061 | MEDIUM | 6.1 | 2.9% | Aug 1, 2017 | An XSS issue was discovered in admin/install.php in MantisBT before 1.3.12 and 2.x before 2.5.2. Some variables under us... |
| CVE-2017-11381 | — | — | 3.1% | Aug 1, 2017 | A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore a... |
| CVE-2017-11380 | — | — | 1.5% | Aug 1, 2017 | Backup archives were found to be encrypted with a static password across different installations, which suggest the same... |
| CVE-2017-11379 | — | — | 0.5% | Aug 1, 2017 | Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1. |
| CVE-2017-11136 | — | — | 0.5% | Aug 1, 2017 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.8... |
| CVE-2017-11135 | — | — | 1.1% | Aug 1, 2017 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.8... |
| CVE-2017-11134 | — | — | 0.8% | Aug 1, 2017 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a l... |
| CVE-2017-11133 | — | — | 0.7% | Aug 1, 2017 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.8... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now