2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6917 | — | — | 0.4% | Mar 15, 2017 | CSRF exists in BigTree CMS 4.2.16 with the value parameter to the admin/settings/update/ page. The Colophon can be chang... |
| CVE-2017-6916 | — | — | 0.4% | Mar 15, 2017 | CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page. The Navigation So... |
| CVE-2017-6915 | — | — | 0.4% | Mar 15, 2017 | CSRF exists in BigTree CMS 4.1.18 with the colophon parameter to the admin/settings/update/ page. The Colophon can be ch... |
| CVE-2017-6914 | — | — | 0.4% | Mar 15, 2017 | CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page. A user can be d... |
| CVE-2017-5522 | — | — | 4.8% | Mar 15, 2017 | Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 al... |
| CVE-2017-6443 | — | — | 3.3% | Mar 15, 2017 | Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web s... |
| CVE-2017-6430 | — | — | 2.0% | Mar 15, 2017 | The compile_tree function in ef_compiler.c in the Etterfilter utility in Ettercap 0.8.2 and earlier allows remote attack... |
| CVE-2017-6429 | HIGH | 7.8 | 2.5% | Mar 15, 2017 | Buffer overflow in the tcpcapinfo utility in Tcpreplay before 4.2.0 Beta 1 allows remote attackers to have unspecified i... |
| CVE-2017-6189 | — | — | 1.2% | Mar 15, 2017 | Untrusted search path vulnerability in Amazon Kindle for PC before 1.19 allows local users to execute arbitrary code and... |
| CVE-2017-5580 | — | — | 0.5% | Mar 15, 2017 | The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS... |
| CVE-2017-5579 | MEDIUM | 6.5 | 0.4% | Mar 15, 2017 | Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS priv... |
| CVE-2017-5578 | MEDIUM | 6.5 | 0.4% | Mar 15, 2017 | Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) a... |
| CVE-2017-5552 | MEDIUM | 6.5 | 0.4% | Mar 15, 2017 | Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) all... |
| CVE-2017-5537 | — | — | 2.3% | Mar 15, 2017 | The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email addres... |
| CVE-2017-5526 | MEDIUM | 6.5 | 0.4% | Mar 15, 2017 | Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial o... |
| CVE-2017-5525 | MEDIUM | 6.5 | 0.4% | Mar 15, 2017 | Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of ... |
| CVE-2017-5496 | — | — | 5.8% | Mar 15, 2017 | Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash. |
| CVE-2017-5359 | — | — | 7.4% | Mar 15, 2017 | EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI. |
| CVE-2017-5358 | — | — | 12.1% | Mar 15, 2017 | Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbi... |
| CVE-2017-6852 | — | — | 1.9% | Mar 15, 2017 | Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote attackers to ... |
| CVE-2017-6851 | — | — | 1.5% | Mar 15, 2017 | The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (inva... |
| CVE-2017-6850 | — | — | 1.8% | Mar 15, 2017 | The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service ... |
| CVE-2017-6849 | — | — | 1.3% | Mar 15, 2017 | The PoDoFo::PdfColorGray::~PdfColorGray function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a deni... |
| CVE-2017-6848 | — | — | 1.3% | Mar 15, 2017 | The PoDoFo::PdfXObject::PdfXObject function in PdfXObject.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial ... |
| CVE-2017-6847 | — | — | 1.3% | Mar 15, 2017 | The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.4 allows remote attackers to cause a denial o... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now