2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-9046 | — | — | 0.6% | May 21, 2017 | winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be ... |
| CVE-2017-9024 | HIGH | 7.5 | 12.2% | May 21, 2017 | Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Tra... |
| CVE-2017-7620 | — | — | 1.4% | May 21, 2017 | MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequen... |
| CVE-2017-9100 | HIGH | 8.8 | 85.5% | May 21, 2017 | login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering mor... |
| CVE-2017-7504 | — | — | 29.3% | May 19, 2017 | HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in... |
| CVE-2017-7475 | MEDIUM | 5.5 | 1.8% | May 19, 2017 | Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph result... |
| CVE-2017-9098 | HIGH | 7.5 | 3.6% | May 19, 2017 | ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an att... |
| CVE-2017-9094 | — | — | 1.3% | May 19, 2017 | The lzw_add_to_dict function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cau... |
| CVE-2017-9093 | — | — | 1.3% | May 19, 2017 | The my_skip_input_data_fn function in imagew-jpeg.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers... |
| CVE-2017-9091 | — | — | 1.2% | May 19, 2017 | /admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA by... |
| CVE-2017-9090 | — | — | 1.2% | May 19, 2017 | reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the... |
| CVE-2017-9083 | — | — | 1.1% | May 19, 2017 | poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte functio... |
| CVE-2017-9080 | — | — | 62.3% | May 19, 2017 | PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile... |
| CVE-2017-7968 | — | — | 0.4% | May 19, 2017 | An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 ... |
| CVE-2017-4979 | — | — | 0.8% | May 19, 2017 | EMC Isilon OneFS 8.0.1.0, OneFS 8.0.0.0 - 8.0.0.2, OneFS 7.2.1.0 - 7.2.1.3, and OneFS 7.2.0.x is affected by an NFS expo... |
| CVE-2017-4978 | — | — | 0.8% | May 19, 2017 | EMC RSA Adaptive Authentication (On-Premise) versions prior to 7.3 P2 (exclusive) contains a fix for a cross-site script... |
| CVE-2017-9079 | — | — | 0.3% | May 19, 2017 | Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file ... |
| CVE-2017-9078 | HIGH | 8.8 | 5.1% | May 19, 2017 | The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double fre... |
| CVE-2017-9077 | HIGH | 7.8 | 0.7% | May 19, 2017 | The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whic... |
| CVE-2017-9076 | HIGH | 7.8 | 0.4% | May 19, 2017 | The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whi... |
| CVE-2017-9075 | HIGH | 7.8 | 0.4% | May 19, 2017 | The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whic... |
| CVE-2017-9074 | HIGH | 7.8 | 0.4% | May 19, 2017 | The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be... |
| CVE-2017-7937 | — | — | 0.7% | May 19, 2017 | An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An atta... |
| CVE-2017-7935 | — | — | 1.2% | May 19, 2017 | A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker ... |
| CVE-2017-7907 | — | — | 0.4% | May 19, 2017 | An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now