2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-11753The GetImageDepth function in MagickCore/attribute.c in ImageMagick 7.0.6-4 might allow remote attackers to cause a deni...
CVE-2017-11752The ReadMAGICKImage function in coders/magick.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of serv...
CVE-2017-11751The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service...
CVE-2017-11750The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denia...
CVE-2017-11692The function "Token& Scanner::peek" in scanner.cpp in yaml-cpp 0.5.3 and earlier allows remote attackers to cause a deni...
CVE-2017-11749HIGH7.8InternetSoft FTP Commander 8.02 and prior has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi...
CVE-2017-11748VIT Spider Player 2.5.3 has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll, olepro32.dll...
CVE-2017-11747main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-roo...
CVE-2017-11746Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to ...
CVE-2017-11744In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicio...
CVE-2017-11742The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local us...
CVE-2017-11737interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are...
CVE-2017-11736SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated u...
CVE-2017-11734A heap-based buffer over-read was found in the function decompileCALLFUNCTION in util/decompile.c in Ming 0.4.8, which a...
CVE-2017-11733A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/de...
CVE-2017-11732A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/de...
CVE-2017-11731An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/...
CVE-2017-11730A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1474) in util/decomp...
CVE-2017-11729A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1440) in util/decomp...
CVE-2017-11728A heap-based buffer over-read was found in the function OpCode (called from decompileSETMEMBER) in util/decompile.c in M...
CVE-2017-11725The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redire...
CVE-2017-11724The ReadMATImage function in coders/mat.c in ImageMagick through 6.9.9-3 and 7.x through 7.0.6-3 has memory leaks involv...
CVE-2017-11723Directory traversal vulnerability in plugins/ImageManager/backend.php in Xinha 0.96, as used in Jojo 4.4.0, allows remot...
CVE-2017-4919VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to ...
CVE-2017-6260NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer helper function where an incorrect c...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now