2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-11753 | — | — | 1.5% | Jul 30, 2017 | The GetImageDepth function in MagickCore/attribute.c in ImageMagick 7.0.6-4 might allow remote attackers to cause a deni... |
| CVE-2017-11752 | — | — | 1.8% | Jul 30, 2017 | The ReadMAGICKImage function in coders/magick.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of serv... |
| CVE-2017-11751 | — | — | 1.8% | Jul 30, 2017 | The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service... |
| CVE-2017-11750 | — | — | 1.8% | Jul 30, 2017 | The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denia... |
| CVE-2017-11692 | — | — | 2.2% | Jul 30, 2017 | The function "Token& Scanner::peek" in scanner.cpp in yaml-cpp 0.5.3 and earlier allows remote attackers to cause a deni... |
| CVE-2017-11749 | HIGH | 7.8 | 0.8% | Jul 30, 2017 | InternetSoft FTP Commander 8.02 and prior has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi... |
| CVE-2017-11748 | — | — | 0.8% | Jul 30, 2017 | VIT Spider Player 2.5.3 has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll, olepro32.dll... |
| CVE-2017-11747 | — | — | 0.3% | Jul 30, 2017 | main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-roo... |
| CVE-2017-11746 | — | — | 1.1% | Jul 30, 2017 | Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to ... |
| CVE-2017-11744 | — | — | 0.6% | Jul 30, 2017 | In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicio... |
| CVE-2017-11742 | — | — | 0.5% | Jul 30, 2017 | The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local us... |
| CVE-2017-11737 | — | — | 0.7% | Jul 29, 2017 | interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are... |
| CVE-2017-11736 | — | — | 1.0% | Jul 29, 2017 | SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated u... |
| CVE-2017-11734 | — | — | 1.0% | Jul 29, 2017 | A heap-based buffer over-read was found in the function decompileCALLFUNCTION in util/decompile.c in Ming 0.4.8, which a... |
| CVE-2017-11733 | — | — | 1.0% | Jul 29, 2017 | A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/de... |
| CVE-2017-11732 | — | — | 1.1% | Jul 29, 2017 | A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/de... |
| CVE-2017-11731 | — | — | 1.0% | Jul 29, 2017 | An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/... |
| CVE-2017-11730 | — | — | 1.1% | Jul 29, 2017 | A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1474) in util/decomp... |
| CVE-2017-11729 | — | — | 1.1% | Jul 29, 2017 | A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1440) in util/decomp... |
| CVE-2017-11728 | — | — | 1.1% | Jul 29, 2017 | A heap-based buffer over-read was found in the function OpCode (called from decompileSETMEMBER) in util/decompile.c in M... |
| CVE-2017-11725 | — | — | 0.6% | Jul 29, 2017 | The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redire... |
| CVE-2017-11724 | — | — | 1.8% | Jul 29, 2017 | The ReadMATImage function in coders/mat.c in ImageMagick through 6.9.9-3 and 7.x through 7.0.6-3 has memory leaks involv... |
| CVE-2017-11723 | — | — | 2.6% | Jul 29, 2017 | Directory traversal vulnerability in plugins/ImageManager/backend.php in Xinha 0.96, as used in Jojo 4.4.0, allows remot... |
| CVE-2017-4919 | — | — | 2.0% | Jul 28, 2017 | VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to ... |
| CVE-2017-6260 | — | — | 0.3% | Jul 28, 2017 | NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer helper function where an incorrect c... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now