2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-9153libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the pnm_load_rawpbm function in input-pnm.c:391:1...
CVE-2017-9152libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the pnm_load_raw function in input-pnm.c:346:41.
CVE-2017-9151libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the pnm_load_ascii function in input-pnm.c:303:12...
CVE-2017-8915sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure a...
CVE-2017-8914sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by...
CVE-2017-8913HIGH8.8The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML ...
CVE-2017-8379MEDIUM6.5Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged u...
CVE-2017-8309HIGH7.5Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memo...
CVE-2017-7288Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inj...
CVE-2017-6821Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecif...
CVE-2017-6813A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing...
CVE-2017-5870Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web s...
CVE-2017-9150The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value...
CVE-2017-1320IBM Tivoli Federated Identity Manager 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2017-1289IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A rem...
CVE-2017-1282IBM Content Navigator & CMIS 2.0 and 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2017-1159IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redire...
CVE-2017-1092IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a...
CVE-2017-9149Metadata Anonymisation Toolkit (MAT) 0.6 and 0.6.1 silently fails to perform "Clean metadata" actions upon invocation fr...
CVE-2017-6891HIGH8.8Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to...
CVE-2017-9147LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cau...
CVE-2017-9146The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before...
CVE-2017-5657Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A ...
CVE-2017-2175Untrusted search path vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to gain...
CVE-2017-2174Cross-site scripting vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to injec...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now