2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-11112 | HIGH | 7.5 | 2.2% | Jul 8, 2017 | In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It co... |
| CVE-2017-11111 | — | — | 1.7% | Jul 8, 2017 | In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer o... |
| CVE-2017-11110 | — | — | 1.2% | Jul 8, 2017 | The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer un... |
| CVE-2017-11109 | — | — | 1.1% | Jul 8, 2017 | Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a cra... |
| CVE-2017-11108 | — | — | 4.9% | Jul 8, 2017 | tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) v... |
| CVE-2017-11107 | MEDIUM | 6.1 | 2.1% | Jul 8, 2017 | phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter. |
| CVE-2017-11104 | MEDIUM | 5.9 | 2.7% | Jul 8, 2017 | Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an... |
| CVE-2017-7512 | — | — | 2.2% | Jul 7, 2017 | Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token witho... |
| CVE-2017-8442 | — | — | 0.9% | Jul 7, 2017 | Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking ... |
| CVE-2017-7660 | — | — | 5.5% | Jul 7, 2017 | Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to cr... |
| CVE-2017-11102 | — | — | 3.3% | Jul 7, 2017 | The ReadOneJNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of servi... |
| CVE-2017-11101 | — | — | 1.4% | Jul 7, 2017 | When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_Relocat... |
| CVE-2017-11100 | — | — | 1.4% | Jul 7, 2017 | When SWFTools 0.9.2 processes a crafted file in swfextract, it can lead to a NULL Pointer Dereference in the swf_FoldSpr... |
| CVE-2017-11099 | — | — | 1.4% | Jul 7, 2017 | When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Violation in the wav_convert2mono... |
| CVE-2017-11098 | — | — | 1.4% | Jul 7, 2017 | When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() funct... |
| CVE-2017-11097 | — | — | 1.4% | Jul 7, 2017 | When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Dereference in the dict_lookup() fun... |
| CVE-2017-11096 | — | — | 1.4% | Jul 7, 2017 | When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_DeleteF... |
| CVE-2017-9631 | HIGH | 7.5 | 3.2% | Jul 7, 2017 | A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.230... |
| CVE-2017-9629 | CRITICAL | 9.8 | 9.8% | Jul 7, 2017 | A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.... |
| CVE-2017-9627 | HIGH | 8.6 | 4.1% | Jul 7, 2017 | An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 20... |
| CVE-2017-6868 | — | — | 4.2% | Jul 7, 2017 | An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthe... |
| CVE-2017-1000381 | HIGH | 7.5 | 3.3% | Jul 7, 2017 | The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read me... |
| CVE-2017-1000082 | CRITICAL | 9.8 | 3.9% | Jul 7, 2017 | systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the servic... |
| CVE-2017-10995 | — | — | 1.8% | Jul 7, 2017 | The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (h... |
| CVE-2017-10994 | — | — | 4.9% | Jul 7, 2017 | Foxit Reader before 8.3.1 and PhantomPDF before 8.3.1 have an Arbitrary Write vulnerability, which allows remote attacke... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now