2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-11347Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP sc...
CVE-2017-11346Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors invo...
CVE-2017-11345Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT...
CVE-2017-11344Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, R...
CVE-2017-11343Due to an incomplete fix for CVE-2012-6125, all versions of CHICKEN Scheme up to and including 4.12.0 are vulnerable to ...
CVE-2017-11342There is an illegal address access in ast.cpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service ...
CVE-2017-11341There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of se...
CVE-2017-11340There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, related to an exit call. A Crafted i...
CVE-2017-11339There is a heap-based buffer overflow in the Image::printIFDStructure function of image.cpp in Exiv2 0.26. A Crafted inp...
CVE-2017-11338There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26. A crafted input wi...
CVE-2017-11337There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26. A crafted input will...
CVE-2017-11336There is a heap-based buffer over-read in the Image::printIFDStructure function in image.cpp in Exiv2 0.26. A Crafted in...
CVE-2017-11335There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes...
CVE-2017-11329GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that i...
CVE-2017-11328Heap buffer overflow in the yr_object_array_set_item() function in object.c in YARA 3.x allows a denial-of-service attac...
CVE-2017-11318Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is...
CVE-2017-11311soundlib/Load_psm.cpp in OpenMPT through 1.26.12.00 and libopenmpt before 0.2.8461-beta26 has a heap buffer overflow wit...
CVE-2017-10605HIGH8.6On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the ...
CVE-2017-10604MEDIUM5.3When the device is configured to perform account lockout with a defined period of time, any unauthenticated user attempt...
CVE-2017-10603HIGH7An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate privileges and run arbi...
CVE-2017-10602HIGH7A buffer overflow vulnerability in Junos OS CLI may allow a local authenticated user with read only privileges and acces...
CVE-2017-10601CRITICAL9.8A specific device configuration can result in a commit failure condition. When this occurs, a user is logged in without ...
CVE-2017-1000363HIGH7.8Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is sta...
CVE-2017-1000362The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It...
CVE-2017-1000081CRITICAL9.8Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code exec...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now