2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-11651 | MEDIUM | 6.1 | 0.7% | Jul 26, 2017 | NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag. |
| CVE-2017-11644 | — | — | 1.6% | Jul 26, 2017 | When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the ReadMATImage() functio... |
| CVE-2017-11643 | — | — | 2.2% | Jul 26, 2017 | GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in coders/cmyk.c when processing multiple fra... |
| CVE-2017-11642 | — | — | 1.8% | Jul 26, 2017 | GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() function in coders/map.c when processing a n... |
| CVE-2017-11641 | — | — | 2.0% | Jul 26, 2017 | GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Pe... |
| CVE-2017-11640 | — | — | 2.7% | Jul 26, 2017 | When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to an address access exception in the WritePTI... |
| CVE-2017-11639 | — | — | 2.7% | Jul 26, 2017 | When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteC... |
| CVE-2017-11638 | — | — | 1.7% | Jul 26, 2017 | GraphicsMagick 1.3.26 has a segmentation violation in the WriteMAPImage() function in coders/map.c when processing a non... |
| CVE-2017-11637 | — | — | 2.1% | Jul 26, 2017 | GraphicsMagick 1.3.26 has a NULL pointer dereference in the WritePCLImage() function in coders/pcl.c during writes of mo... |
| CVE-2017-11636 | — | — | 3.1% | Jul 26, 2017 | GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frame... |
| CVE-2017-11631 | — | — | 1.0% | Jul 26, 2017 | dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter. |
| CVE-2017-11630 | — | — | 1.8% | Jul 26, 2017 | dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via di... |
| CVE-2017-11629 | — | — | 1.9% | Jul 26, 2017 | dayrui FineCms through 5.0.10 has Cross Site Scripting (XSS) in controllers/api.php via the function parameter in a c=ap... |
| CVE-2017-11613 | — | — | 2.7% | Jul 26, 2017 | In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a de... |
| CVE-2017-11628 | — | — | 3.4% | Jul 25, 2017 | In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() f... |
| CVE-2017-11627 | — | — | 1.3% | Jul 25, 2017 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of servic... |
| CVE-2017-11626 | — | — | 1.2% | Jul 25, 2017 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of servic... |
| CVE-2017-11625 | — | — | 1.3% | Jul 25, 2017 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of servic... |
| CVE-2017-11624 | — | — | 1.2% | Jul 25, 2017 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of servic... |
| CVE-2017-9233 | HIGH | 7.5 | 8.7% | Jul 25, 2017 | XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the p... |
| CVE-2017-6755 | — | — | 1.3% | Jul 25, 2017 | A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning (PCP) Tool could allow an unauthenticate... |
| CVE-2017-6753 | — | — | 6.0% | Jul 25, 2017 | A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, ... |
| CVE-2017-6751 | HIGH | 7.5 | 2.0% | Jul 25, 2017 | A vulnerability in the web proxy functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated,... |
| CVE-2017-6750 | — | — | 2.7% | Jul 25, 2017 | A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to ... |
| CVE-2017-6749 | — | — | 1.2% | Jul 25, 2017 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now