2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-0196An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive inform...
CVE-2017-0152A remote code execution vulnerability exists in the way affected Microsoft scripting engine render when handling objects...
CVE-2017-0028A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The ...
CVE-2017-11310The read_user_chunk_callback function in coders\png.c in ImageMagick 7.0.6-1 Q16 2017-06-21 (beta) has memory leak vulne...
CVE-2017-9789When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memo...
CVE-2017-9788In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'D...
CVE-2017-6249An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute...
CVE-2017-9787When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to up...
CVE-2017-7672If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a spe...
CVE-2017-1308IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download fil...
CVE-2017-7529HIGH7.5Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range fi...
CVE-2017-11103HIGH8.1Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service...
CVE-2017-11173HIGH8.8Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS request...
CVE-2017-11202FineCMS through 2017-07-12 allows XSS in visitors.php because JavaScript in visited URLs is not restricted either during...
CVE-2017-11201application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS a...
CVE-2017-11200SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter...
CVE-2017-11198Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows rem...
CVE-2017-11174In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL...
CVE-2017-11196Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF t...
CVE-2017-11195Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME e...
CVE-2017-11194Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter o...
CVE-2017-11193Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands suc...
CVE-2017-2863HIGH7.8An out-of-bounds write vulnerability exists in the PDF parsing functionality of Infix 7.1.5. A specially crafted PDF fil...
CVE-2017-2820HIGH8.8An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Pop...
CVE-2017-2818HIGH7.5An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now