2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7942 | — | — | 1.9% | Apr 18, 2017 | The ReadAVSImage function in avs.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memo... |
| CVE-2017-7941 | — | — | 2.5% | Apr 18, 2017 | The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memo... |
| CVE-2017-7940 | — | — | 0.9% | Apr 18, 2017 | The iw_read_gif_file function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to co... |
| CVE-2017-7939 | — | — | 1.1% | Apr 18, 2017 | The read_next_pam_token function in imagew-pnm.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to... |
| CVE-2017-7897 | — | — | 1.8% | Apr 18, 2017 | A cross-site scripting (XSS) vulnerability in the MantisBT (2.3.x before 2.3.2) Timeline include page, used in My View (... |
| CVE-2017-5656 | — | — | 6.8% | Apr 18, 2017 | Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation ... |
| CVE-2017-5653 | — | — | 11.2% | Apr 18, 2017 | JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response w... |
| CVE-2017-7896 | — | — | 4.3% | Apr 18, 2017 | Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS. |
| CVE-2017-7645 | HIGH | 7.5 | 5.8% | Apr 18, 2017 | The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a deni... |
| CVE-2017-5662 | — | — | 4.1% | Apr 18, 2017 | In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary us... |
| CVE-2017-5661 | — | — | 3.0% | Apr 18, 2017 | In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users ... |
| CVE-2017-7892 | — | — | 1.3% | Apr 17, 2017 | Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can tri... |
| CVE-2017-5645 | CRITICAL | 9.8 | 89.0% | Apr 17, 2017 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events... |
| CVE-2017-1161 | — | — | 1.5% | Apr 17, 2017 | IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper va... |
| CVE-2017-1160 | — | — | 0.5% | Apr 17, 2017 | IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. Thi... |
| CVE-2017-5659 | — | — | 3.0% | Apr 17, 2017 | Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked enco... |
| CVE-2017-5651 | — | — | 7.8% | Apr 17, 2017 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regressi... |
| CVE-2017-5650 | — | — | 8.3% | Apr 17, 2017 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did ... |
| CVE-2017-5648 | — | — | 12.7% | Apr 17, 2017 | While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.... |
| CVE-2017-5647 | — | — | 16.8% | Apr 17, 2017 | A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.... |
| CVE-2017-7891 | — | — | 0.7% | Apr 17, 2017 | sourcebans-pp (SourceBans++) 1.5.4.7 has XSS in admin.comms.php via the rebanid parameter. |
| CVE-2017-7889 | HIGH | 7.8 | 0.3% | Apr 17, 2017 | The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism... |
| CVE-2017-7885 | — | — | 1.2% | Apr 17, 2017 | Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure o... |
| CVE-2017-7615 | HIGH | 8.8 | 90.9% | Apr 16, 2017 | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value ... |
| CVE-2017-7882 | — | — | 2.4% | Apr 15, 2017 | LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/h... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now