2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-6003dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.
CVE-2017-6002Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS int...
CVE-2017-5622With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts wit...
CVE-2017-2645In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
CVE-2017-2644In Moodle 3.x, XSS can occur via evidence of prior learning.
CVE-2017-2643In Moodle 3.2.x, global search displays user names for unauthenticated users.
CVE-2017-2641In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
CVE-2017-7266Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which ...
CVE-2017-7264MEDIUM5.3Use-after-free vulnerability in the fz_subsample_pixmap function in fitz/pixmap.c in Artifex MuPDF 1.10a allows remote a...
CVE-2017-7263The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-b...
CVE-2017-7259Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2017-7262The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system ...
CVE-2017-7261The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does...
CVE-2017-7257XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Som...
CVE-2017-7256XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_summary parameter. Som...
CVE-2017-7255XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someo...
CVE-2017-7243Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending...
CVE-2017-7240An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typi...
CVE-2017-5511CRITICAL9.8coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which tri...
CVE-2017-5510HIGH7.8coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an...
CVE-2017-5509HIGH7.8coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an...
CVE-2017-5508Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows ...
CVE-2017-5507HIGH7.5Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote attackers to cause a deni...
CVE-2017-5506HIGH7.8Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a cr...
CVE-2017-5337Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now