2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-2806MEDIUM4.3An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functiona...
CVE-2017-2784HIGH8.1An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before ...
CVE-2017-7718MEDIUM5.5hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of ser...
CVE-2017-5190NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtu...
CVE-2017-7982Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote...
CVE-2017-7938MEDIUM6.6Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau...
CVE-2017-7692SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a...
CVE-2017-5181Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7692. Reason: This candidate is a reservation d...
CVE-2017-7283An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a special...
CVE-2017-7282An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.p...
CVE-2017-6919Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Servi...
CVE-2017-7979The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.1...
CVE-2017-7978Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by ...
CVE-2017-7976Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose fu...
CVE-2017-7975Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_b...
CVE-2017-7964Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for ...
CVE-2017-7963The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial o...
CVE-2017-7962The iwgif_read_image function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to ca...
CVE-2017-7961HIGH7.8The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable v...
CVE-2017-7960The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial...
CVE-2017-7948Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of ser...
CVE-2017-7850Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions...
CVE-2017-7849Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permission...
CVE-2017-7946The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial o...
CVE-2017-7943The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memo...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now