2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-9469In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one b...
CVE-2017-9468In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer....
CVE-2017-9465The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read an...
CVE-2017-9462HIGH8.8In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and conse...
CVE-2017-9461smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop w...
CVE-2017-9452Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbi...
CVE-2017-9451Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbi...
CVE-2017-9422Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-8920. Reason: This candidate is a reservation ...
CVE-2017-8920irc.cgi in CGI:IRC before 0.5.12 reflects user-supplied input from the R parameter without proper output encoding, aka X...
CVE-2017-5243The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired al...
CVE-2017-9449SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL com...
CVE-2017-9448Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbi...
CVE-2017-9332The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors invo...
CVE-2017-8083CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for w...
CVE-2017-7515poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of...
CVE-2017-5664The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is conf...
CVE-2017-9444BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user infor...
CVE-2017-9443HIGH8.8BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables objec...
CVE-2017-9442BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package co...
CVE-2017-9441LOW2.7Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to in...
CVE-2017-9420Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attacker...
CVE-2017-9440In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPSDChannel in coders/psd.c, which allows attackers t...
CVE-2017-9439In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPDBImage in coders/pdb.c, which allows attackers to ...
CVE-2017-9438libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption)...
CVE-2017-1000368Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_proc...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now