2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6313 | HIGH | 7.1 | 1.9% | Mar 10, 2017 | Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause ... |
| CVE-2017-6312 | MEDIUM | 5.5 | 2.0% | Mar 10, 2017 | Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation... |
| CVE-2017-6311 | HIGH | 7.5 | 3.5% | Mar 10, 2017 | gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer der... |
| CVE-2017-5872 | — | — | 1.5% | Mar 10, 2017 | The TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 57.1 before 57.152, 58.1 before 58.142, or 5... |
| CVE-2017-6465 | — | — | 50.3% | Mar 10, 2017 | Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP serv... |
| CVE-2017-4960 | — | — | 1.6% | Mar 10, 2017 | An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and ... |
| CVE-2017-6797 | — | — | 2.3% | Mar 10, 2017 | A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 a... |
| CVE-2017-6591 | — | — | 0.7% | Mar 9, 2017 | There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field. |
| CVE-2017-6590 | — | — | 0.3% | Mar 9, 2017 | An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS,... |
| CVE-2017-6589 | — | — | 0.7% | Mar 9, 2017 | EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example att... |
| CVE-2017-6529 | — | — | 2.9% | Mar 9, 2017 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID pa... |
| CVE-2017-6528 | — | — | 3.4% | Mar 9, 2017 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/... |
| CVE-2017-6527 | — | — | 56.6% | Mar 9, 2017 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal att... |
| CVE-2017-6526 | — | — | 57.4% | Mar 9, 2017 | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution throug... |
| CVE-2017-6432 | — | — | 1.0% | Mar 9, 2017 | An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which ... |
| CVE-2017-6578 | — | — | 1.7% | Mar 9, 2017 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor... |
| CVE-2017-6577 | — | — | 1.7% | Mar 9, 2017 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor... |
| CVE-2017-6576 | — | — | 1.7% | Mar 9, 2017 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor... |
| CVE-2017-6575 | — | — | 1.7% | Mar 9, 2017 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor... |
| CVE-2017-6574 | — | — | 1.7% | Mar 9, 2017 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor... |
| CVE-2017-6573 | — | — | 1.7% | Mar 9, 2017 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor... |
| CVE-2017-6572 | — | — | 1.7% | Mar 9, 2017 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor... |
| CVE-2017-6571 | — | — | 1.7% | Mar 9, 2017 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor... |
| CVE-2017-6570 | — | — | 1.7% | Mar 9, 2017 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor... |
| CVE-2017-6562 | — | — | 0.8% | Mar 9, 2017 | XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now