2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5640 | — | — | 2.9% | Jul 10, 2017 | It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 coul... |
| CVE-2017-7175 | — | — | 6.5% | Jul 10, 2017 | NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt pa... |
| CVE-2017-7670 | — | — | 4.8% | Jul 10, 2017 | The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial ... |
| CVE-2017-11166 | — | — | 1.4% | Jul 10, 2017 | The ReadXWDImage function in coders\xwd.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory e... |
| CVE-2017-11163 | — | — | 1.3% | Jul 10, 2017 | Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to in... |
| CVE-2017-9791 | CRITICAL | 9.8 | 98.9% | Jul 10, 2017 | The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe... |
| CVE-2017-1398 | — | — | 1.0% | Jul 10, 2017 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker ... |
| CVE-2017-1337 | — | — | 1.5% | Jul 10, 2017 | IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-For... |
| CVE-2017-1284 | — | — | 0.3% | Jul 10, 2017 | IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to obtain sensitive infor... |
| CVE-2017-11147 | CRITICAL | 9.1 | 4.7% | Jul 10, 2017 | In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious arch... |
| CVE-2017-11146 | — | — | — | Jul 10, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-11145 | — | — | 4.8% | Jul 10, 2017 | In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsi... |
| CVE-2017-11144 | — | — | 6.2% | Jul 10, 2017 | In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, the openssl extension PEM sealing code did not check th... |
| CVE-2017-11143 | — | — | 6.8% | Jul 10, 2017 | In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able ... |
| CVE-2017-11142 | — | — | 8.3% | Jul 10, 2017 | In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial o... |
| CVE-2017-11141 | — | — | 1.7% | Jul 10, 2017 | The ReadMATImage function in coders\mat.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory e... |
| CVE-2017-11140 | — | — | 1.8% | Jul 10, 2017 | The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a... |
| CVE-2017-11139 | — | — | 2.7% | Jul 10, 2017 | GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c. |
| CVE-2017-11126 | — | — | 1.4% | Jul 10, 2017 | The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of se... |
| CVE-2017-11125 | — | — | 1.9% | Jul 10, 2017 | libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_get_path function in util.c. |
| CVE-2017-11124 | — | — | 1.9% | Jul 10, 2017 | libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_unserialize function in archive.c. |
| CVE-2017-8003 | — | — | 2.6% | Jul 9, 2017 | EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. A remote authenticated high privileged... |
| CVE-2017-8002 | — | — | 2.3% | Jul 9, 2017 | EMC Data Protection Advisor prior to 6.4 contains multiple blind SQL injection vulnerabilities. A remote authenticated a... |
| CVE-2017-4976 | — | — | 1.8% | Jul 9, 2017 | EMC ESRS Policy Manager prior to 6.8 contains an undocumented account (OpenDS admin) with a default password. A remote a... |
| CVE-2017-11113 | HIGH | 7.5 | 2.4% | Jul 8, 2017 | In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lea... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now