2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-3741In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the t...
CVE-2017-3740In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system...
CVE-2017-9409In ImageMagick 7.0.5-5, the ReadMPCImage function in mpc.c allows attackers to cause a denial of service (memory leak) v...
CVE-2017-9408In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows at...
CVE-2017-9407In ImageMagick 7.0.5-5, the ReadPALMImage function in palm.c allows attackers to cause a denial of service (memory leak)...
CVE-2017-9406In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to c...
CVE-2017-9405In ImageMagick 7.0.5-5, the ReadICONImage function in icon.c:452 allows attackers to cause a denial of service (memory l...
CVE-2017-9404In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg....
CVE-2017-9403In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, whi...
CVE-2017-0896Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zuli...
CVE-2017-9380HIGH8.8OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code...
CVE-2017-9379Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-st...
CVE-2017-9378BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance b...
CVE-2017-9372PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13...
CVE-2017-6039A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all versions prior to v6.87. ...
CVE-2017-9366Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Base/Dashboard/Dashboar...
CVE-2017-9365CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/p...
CVE-2017-9364Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, ...
CVE-2017-9363Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code...
CVE-2017-9361WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.
CVE-2017-9360WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.
CVE-2017-9359The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certifi...
CVE-2017-9358A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certifie...
CVE-2017-9354In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash. This was addressed in epan/dissectors/p...
CVE-2017-9353In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by vali...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now