2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-9046winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be ...
CVE-2017-9024HIGH7.5Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Tra...
CVE-2017-7620MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequen...
CVE-2017-9100HIGH8.8login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering mor...
CVE-2017-7504HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in...
CVE-2017-7475MEDIUM5.5Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph result...
CVE-2017-9098HIGH7.5ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an att...
CVE-2017-9094The lzw_add_to_dict function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cau...
CVE-2017-9093The my_skip_input_data_fn function in imagew-jpeg.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers...
CVE-2017-9091/admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA by...
CVE-2017-9090reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the...
CVE-2017-9083poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte functio...
CVE-2017-9080PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile...
CVE-2017-7968An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 ...
CVE-2017-4979EMC Isilon OneFS 8.0.1.0, OneFS 8.0.0.0 - 8.0.0.2, OneFS 7.2.1.0 - 7.2.1.3, and OneFS 7.2.0.x is affected by an NFS expo...
CVE-2017-4978EMC RSA Adaptive Authentication (On-Premise) versions prior to 7.3 P2 (exclusive) contains a fix for a cross-site script...
CVE-2017-9079Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file ...
CVE-2017-9078HIGH8.8The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double fre...
CVE-2017-9077HIGH7.8The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whic...
CVE-2017-9076HIGH7.8The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whi...
CVE-2017-9075HIGH7.8The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whic...
CVE-2017-9074HIGH7.8The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be...
CVE-2017-7937An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An atta...
CVE-2017-7935A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker ...
CVE-2017-7907An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now