2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-11474 | — | — | 1.4% | Jul 20, 2017 | GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via a... |
| CVE-2017-11473 | HIGH | 7.8 | 0.4% | Jul 20, 2017 | Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 ... |
| CVE-2017-11472 | — | — | 0.4% | Jul 20, 2017 | The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the ope... |
| CVE-2017-11471 | — | — | 1.5% | Jul 20, 2017 | IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the el... |
| CVE-2017-11470 | — | — | 1.5% | Jul 20, 2017 | IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the... |
| CVE-2017-11469 | — | — | 4.9% | Jul 20, 2017 | get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter. |
| CVE-2017-10676 | — | — | 1.1% | Jul 20, 2017 | On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username paramet... |
| CVE-2017-9765 | — | — | 21.9% | Jul 20, 2017 | Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and ot... |
| CVE-2017-11467 | — | — | 73.1% | Jul 20, 2017 | OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which a... |
| CVE-2017-11466 | — | — | 7.7% | Jul 20, 2017 | Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remo... |
| CVE-2017-11465 | — | — | 1.7% | Jul 19, 2017 | The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid wri... |
| CVE-2017-11464 | — | — | 1.3% | Jul 19, 2017 | A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of ... |
| CVE-2017-1309 | — | — | 0.2% | Jul 19, 2017 | IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be rea... |
| CVE-2017-1224 | — | — | 1.3% | Jul 19, 2017 | IBM Tivoli Endpoint Manager uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h... |
| CVE-2017-1223 | — | — | 1.4% | Jul 19, 2017 | IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By... |
| CVE-2017-1219 | — | — | 2.1% | Jul 19, 2017 | IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A re... |
| CVE-2017-1218 | — | — | 0.9% | Jul 19, 2017 | IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicio... |
| CVE-2017-1203 | — | — | 1.3% | Jul 19, 2017 | IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications is vulnerable to cross-site scripting.... |
| CVE-2017-7977 | CRITICAL | 9.8 | 2.4% | Jul 19, 2017 | The Screensavercc component in eLux RP before 5.5.0 allows attackers to bypass intended configuration restrictions and e... |
| CVE-2017-9764 | — | — | 0.8% | Jul 19, 2017 | Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2017-11456 | — | — | 8.8% | Jul 19, 2017 | Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticate... |
| CVE-2017-11450 | HIGH | 8.8 | 2.4% | Jul 19, 2017 | coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to cause a denial of service (application crash) or ... |
| CVE-2017-11449 | HIGH | 8.8 | 3.4% | Jul 19, 2017 | coders/mpc.c in ImageMagick before 7.0.6-1 does not enable seekable streams and thus cannot validate blob sizes, which a... |
| CVE-2017-11448 | MEDIUM | 6.5 | 2.7% | Jul 19, 2017 | The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive in... |
| CVE-2017-11447 | MEDIUM | 6.5 | 2.2% | Jul 19, 2017 | The ReadSCREENSHOTImage function in coders/screenshot.c in ImageMagick before 7.0.6-1 has memory leaks, causing denial o... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now