2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-9062In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
CVE-2017-9061In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files,...
CVE-2017-7433An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated at...
CVE-2017-9059The NFSv4 implementation in the Linux kernel through 4.11.1 allows local users to cause a denial of service (resource co...
CVE-2017-9058In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZ...
CVE-2017-9055CRITICAL9.8An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were ...
CVE-2017-9054CRITICAL9.8An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb128_chk() a byte poin...
CVE-2017-9053CRITICAL9.1An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_rea...
CVE-2017-9052CRITICAL9.8An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_form...
CVE-2017-9051libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk fun...
CVE-2017-9050HIGH7.5libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in d...
CVE-2017-9049HIGH7.5libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function...
CVE-2017-9048HIGH7.5libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementConte...
CVE-2017-9047A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid...
CVE-2017-9045The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.c...
CVE-2017-8769MEDIUM4.6Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Document...
CVE-2017-8338A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU v...
CVE-2017-6195Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Tra...
CVE-2017-9044The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote attackers to cause a...
CVE-2017-9043readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type unsigned long" issue, which might allow re...
CVE-2017-9042readelf.c in GNU Binutils 2017-04-12 has a "cannot be represented in type long" issue, which might allow remote attacker...
CVE-2017-9041GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application cras...
CVE-2017-9040GNU Binutils 2017-04-03 allows remote attackers to cause a denial of service (NULL pointer dereference and application c...
CVE-2017-9039GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file with ...
CVE-2017-9038GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application cras...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now