2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-9469 | — | — | 6.1% | Jun 7, 2017 | In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one b... |
| CVE-2017-9468 | — | — | 3.2% | Jun 7, 2017 | In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer.... |
| CVE-2017-9465 | — | — | 1.2% | Jun 6, 2017 | The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read an... |
| CVE-2017-9462 | HIGH | 8.8 | 21.5% | Jun 6, 2017 | In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and conse... |
| CVE-2017-9461 | — | — | 4.2% | Jun 6, 2017 | smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop w... |
| CVE-2017-9452 | — | — | 0.8% | Jun 6, 2017 | Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbi... |
| CVE-2017-9451 | — | — | 0.7% | Jun 6, 2017 | Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbi... |
| CVE-2017-9422 | — | — | — | Jun 6, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-8920. Reason: This candidate is a reservation ... |
| CVE-2017-8920 | — | — | 0.7% | Jun 6, 2017 | irc.cgi in CGI:IRC before 0.5.12 reflects user-supplied input from the R parameter without proper output encoding, aka X... |
| CVE-2017-5243 | — | — | 0.5% | Jun 6, 2017 | The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired al... |
| CVE-2017-9449 | — | — | 1.1% | Jun 6, 2017 | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL com... |
| CVE-2017-9448 | — | — | 0.6% | Jun 6, 2017 | Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbi... |
| CVE-2017-9332 | — | — | 0.6% | Jun 6, 2017 | The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors invo... |
| CVE-2017-8083 | — | — | 0.3% | Jun 6, 2017 | CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for w... |
| CVE-2017-7515 | — | — | 1.1% | Jun 6, 2017 | poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of... |
| CVE-2017-5664 | — | — | 16.6% | Jun 6, 2017 | The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is conf... |
| CVE-2017-9444 | — | — | 0.5% | Jun 5, 2017 | BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user infor... |
| CVE-2017-9443 | HIGH | 8.8 | 1.3% | Jun 5, 2017 | BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables objec... |
| CVE-2017-9442 | — | — | 2.5% | Jun 5, 2017 | BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package co... |
| CVE-2017-9441 | LOW | 2.7 | 0.6% | Jun 5, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to in... |
| CVE-2017-9420 | — | — | 1.3% | Jun 5, 2017 | Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attacker... |
| CVE-2017-9440 | — | — | 1.5% | Jun 5, 2017 | In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPSDChannel in coders/psd.c, which allows attackers t... |
| CVE-2017-9439 | — | — | 1.5% | Jun 5, 2017 | In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPDBImage in coders/pdb.c, which allows attackers to ... |
| CVE-2017-9438 | — | — | 2.6% | Jun 5, 2017 | libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption)... |
| CVE-2017-1000368 | — | — | 0.6% | Jun 5, 2017 | Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_proc... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now