2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-11184 | — | — | 1.6% | Jul 28, 2017 | SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter. |
| CVE-2017-11183 | — | — | 1.3% | Jul 28, 2017 | front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted... |
| CVE-2017-8870 | — | — | 13.7% | Jul 27, 2017 | Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file. |
| CVE-2017-8869 | — | — | 15.9% | Jul 27, 2017 | Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file. |
| CVE-2017-11665 | — | — | 2.4% | Jul 27, 2017 | The ff_amf_get_field_value function in libavformat/rtmppkt.c in FFmpeg 3.3.2 allows remote RTMP servers to cause a denia... |
| CVE-2017-9614 | HIGH | 8.8 | 8.2% | Jul 27, 2017 | The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service... |
| CVE-2017-9545 | — | — | 1.2% | Jul 27, 2017 | The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote attackers to cause a denial of service (buf... |
| CVE-2017-9412 | — | — | 4.0% | Jul 27, 2017 | The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of ser... |
| CVE-2017-9411 | — | — | — | Jul 27, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9100. Reason: This candidate is a duplicate of C... |
| CVE-2017-9410 | — | — | — | Jul 27, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9101. Reason: This candidate is a duplicate of C... |
| CVE-2017-9260 | — | — | 3.9% | Jul 27, 2017 | The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attack... |
| CVE-2017-9259 | — | — | 6.2% | Jul 27, 2017 | The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote atta... |
| CVE-2017-9258 | — | — | 4.2% | Jul 27, 2017 | The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to... |
| CVE-2017-11691 | — | — | 2.0% | Jul 27, 2017 | Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary... |
| CVE-2017-11687 | — | — | 1.3% | Jul 27, 2017 | Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho Manage... |
| CVE-2017-11686 | — | — | 2.3% | Jul 27, 2017 | Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password vi... |
| CVE-2017-11685 | — | — | 1.3% | Jul 27, 2017 | Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine ... |
| CVE-2017-11684 | — | — | 1.6% | Jul 27, 2017 | There is an illegal address access in the build_table function in libavcodec/bitstream.c of Libav 12.1 that will lead to... |
| CVE-2017-11683 | MEDIUM | 6.5 | 2.7% | Jul 27, 2017 | There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 tha... |
| CVE-2017-11682 | MEDIUM | 6.1 | 0.8% | Jul 27, 2017 | Stored Cross-site scripting vulnerability in Hashtopussy 0.4.0 allows remote attackers to inject arbitrary web script or... |
| CVE-2017-11681 | — | — | 1.2% | Jul 27, 2017 | Incorrect Access Control vulnerability in Hashtopussy 0.4.0 allows remote authenticated users to execute actions that sh... |
| CVE-2017-11680 | — | — | 0.5% | Jul 27, 2017 | Cross-Site Request Forgery (CSRF) exists in Hashtopussy 0.4.0, allowing an admin password change via users.php. |
| CVE-2017-11679 | — | — | 0.7% | Jul 27, 2017 | Cross-Site Request Forgery (CSRF) exists in Hashtopus 1.5g via the password parameter to admin.php in an a=config action... |
| CVE-2017-11678 | — | — | 1.7% | Jul 27, 2017 | SQL injection vulnerability in Hashtopus 1.5g allows remote authenticated users to execute arbitrary SQL commands via th... |
| CVE-2017-11677 | — | — | 0.9% | Jul 27, 2017 | Cross-site scripting (XSS) vulnerability in Hashtopus 1.5g allows remote attackers to inject arbitrary web script or HTM... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now