2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-7942The ReadAVSImage function in avs.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memo...
CVE-2017-7941The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memo...
CVE-2017-7940The iw_read_gif_file function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to co...
CVE-2017-7939The read_next_pam_token function in imagew-pnm.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to...
CVE-2017-7897A cross-site scripting (XSS) vulnerability in the MantisBT (2.3.x before 2.3.2) Timeline include page, used in My View (...
CVE-2017-5656Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation ...
CVE-2017-5653JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response w...
CVE-2017-7896Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.
CVE-2017-7645HIGH7.5The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a deni...
CVE-2017-5662In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary us...
CVE-2017-5661In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users ...
CVE-2017-7892Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can tri...
CVE-2017-5645CRITICAL9.8In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events...
CVE-2017-1161IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper va...
CVE-2017-1160IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. Thi...
CVE-2017-5659Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked enco...
CVE-2017-5651In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regressi...
CVE-2017-5650In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did ...
CVE-2017-5648While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0....
CVE-2017-5647A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8....
CVE-2017-7891sourcebans-pp (SourceBans++) 1.5.4.7 has XSS in admin.comms.php via the rebanid parameter.
CVE-2017-7889HIGH7.8The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism...
CVE-2017-7885Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure o...
CVE-2017-7615HIGH8.8MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value ...
CVE-2017-7882LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/h...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now