2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-2806 | MEDIUM | 4.3 | 0.9% | Apr 20, 2017 | An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functiona... |
| CVE-2017-2784 | HIGH | 8.1 | 3.4% | Apr 20, 2017 | An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before ... |
| CVE-2017-7718 | MEDIUM | 5.5 | 0.5% | Apr 20, 2017 | hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of ser... |
| CVE-2017-5190 | — | — | 0.7% | Apr 20, 2017 | NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtu... |
| CVE-2017-7982 | — | — | 1.5% | Apr 20, 2017 | Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote... |
| CVE-2017-7938 | MEDIUM | 6.6 | 5.0% | Apr 20, 2017 | Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau... |
| CVE-2017-7692 | — | — | 32.2% | Apr 20, 2017 | SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a... |
| CVE-2017-5181 | — | — | — | Apr 20, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7692. Reason: This candidate is a reservation d... |
| CVE-2017-7283 | — | — | 4.3% | Apr 20, 2017 | An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a special... |
| CVE-2017-7282 | — | — | 4.3% | Apr 20, 2017 | An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.p... |
| CVE-2017-6919 | — | — | 1.6% | Apr 20, 2017 | Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Servi... |
| CVE-2017-7979 | — | — | 0.4% | Apr 19, 2017 | The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.1... |
| CVE-2017-7978 | — | — | 1.1% | Apr 19, 2017 | Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by ... |
| CVE-2017-7976 | — | — | 1.1% | Apr 19, 2017 | Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose fu... |
| CVE-2017-7975 | — | — | 1.7% | Apr 19, 2017 | Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_b... |
| CVE-2017-7964 | — | — | 2.5% | Apr 19, 2017 | Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for ... |
| CVE-2017-7963 | — | — | 1.7% | Apr 19, 2017 | The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial o... |
| CVE-2017-7962 | — | — | 1.2% | Apr 19, 2017 | The iwgif_read_image function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to ca... |
| CVE-2017-7961 | HIGH | 7.8 | 2.0% | Apr 19, 2017 | The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable v... |
| CVE-2017-7960 | — | — | 2.0% | Apr 19, 2017 | The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial... |
| CVE-2017-7948 | — | — | 1.6% | Apr 19, 2017 | Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of ser... |
| CVE-2017-7850 | — | — | 0.3% | Apr 19, 2017 | Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions... |
| CVE-2017-7849 | — | — | 0.3% | Apr 19, 2017 | Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permission... |
| CVE-2017-7946 | — | — | 0.9% | Apr 18, 2017 | The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial o... |
| CVE-2017-7943 | — | — | 2.8% | Apr 18, 2017 | The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memo... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now