2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-11446 | — | — | 1.7% | Jul 19, 2017 | The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite loop vulnerability that can cause CPU e... |
| CVE-2017-11445 | — | — | 1.1% | Jul 19, 2017 | Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array. |
| CVE-2017-11444 | — | — | 13.1% | Jul 19, 2017 | Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array. |
| CVE-2017-11441 | — | — | 0.5% | Jul 19, 2017 | The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27,... |
| CVE-2017-11440 | — | — | 2.0% | Jul 19, 2017 | In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin... |
| CVE-2017-11439 | — | — | 0.6% | Jul 19, 2017 | In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter. |
| CVE-2017-11436 | CRITICAL | 9.8 | 2.0% | Jul 19, 2017 | D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attacke... |
| CVE-2017-11435 | CRITICAL | 9.8 | 10.1% | Jul 19, 2017 | The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted req... |
| CVE-2017-10801 | — | — | 0.6% | Jul 19, 2017 | phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO to the search/tag/ URI. |
| CVE-2017-9245 | — | — | 1.1% | Jul 19, 2017 | The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffin... |
| CVE-2017-11411 | — | — | 1.3% | Jul 18, 2017 | In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This... |
| CVE-2017-11410 | — | — | 1.3% | Jul 18, 2017 | In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by pa... |
| CVE-2017-11409 | — | — | 2.3% | Jul 18, 2017 | In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/p... |
| CVE-2017-11408 | — | — | 2.0% | Jul 18, 2017 | In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the AMQP dissector could crash. This was addressed in epan/dissectors/p... |
| CVE-2017-11407 | — | — | 2.8% | Jul 18, 2017 | In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/pac... |
| CVE-2017-11406 | — | — | 3.0% | Jul 18, 2017 | In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop. This was addressed... |
| CVE-2017-11423 | — | — | 2.1% | Jul 18, 2017 | The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allow... |
| CVE-2017-10708 | — | — | 2.1% | Jul 18, 2017 | An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then ... |
| CVE-2017-11421 | — | — | 0.6% | Jul 18, 2017 | gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "B... |
| CVE-2017-5247 | — | — | 0.5% | Jul 18, 2017 | Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field. An authenticated user with per... |
| CVE-2017-5246 | — | — | 0.6% | Jul 18, 2017 | Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated ... |
| CVE-2017-7506 | — | — | 4.2% | Jul 18, 2017 | spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from... |
| CVE-2017-6320 | HIGH | 8.8 | 11.1% | Jul 18, 2017 | A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (20... |
| CVE-2017-5245 | — | — | — | Jul 18, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-10962 | — | — | 0.6% | Jul 18, 2017 | REDCap before 7.5.1 has XSS via the query string. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now