2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6499 | — | — | 1.3% | Mar 6, 2017 | An issue was discovered in Magick++ in ImageMagick 6.9.7. A specially crafted file creating a nested exception could lea... |
| CVE-2017-6498 | — | — | 1.3% | Mar 6, 2017 | An issue was discovered in ImageMagick 6.9.7. Incorrect TGA files could trigger assertion failures, thus leading to DoS. |
| CVE-2017-6497 | — | — | 2.0% | Mar 6, 2017 | An issue was discovered in ImageMagick 6.9.7. A specially crafted psd file could lead to a NULL pointer dereference (thu... |
| CVE-2017-6416 | — | — | 10.8% | Mar 6, 2017 | An issue was discovered in SysGauge 1.5.18. A buffer overflow vulnerability in SMTP connection verification leads to arb... |
| CVE-2017-6351 | — | — | 7.1% | Mar 6, 2017 | The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password... |
| CVE-2017-6334 | HIGH | 8.8 | 72.2% | Mar 6, 2017 | dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar... |
| CVE-2017-6446 | — | — | 0.7% | Mar 5, 2017 | XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order paramete... |
| CVE-2017-6492 | — | — | 1.4% | Mar 5, 2017 | SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_ca... |
| CVE-2017-6491 | MEDIUM | 6.1 | 0.8% | Mar 5, 2017 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficie... |
| CVE-2017-6490 | MEDIUM | 6.1 | 0.8% | Mar 5, 2017 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficie... |
| CVE-2017-6489 | MEDIUM | 6.1 | 0.8% | Mar 5, 2017 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficie... |
| CVE-2017-6488 | MEDIUM | 6.1 | 0.8% | Mar 5, 2017 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficie... |
| CVE-2017-6487 | MEDIUM | 6.1 | 0.8% | Mar 5, 2017 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficie... |
| CVE-2017-6486 | — | — | 0.7% | Mar 5, 2017 | A Cross-Site Scripting (XSS) issue was discovered in reasoncms before 4.7.1. The vulnerability exists due to insufficien... |
| CVE-2017-6485 | — | — | 0.7% | Mar 5, 2017 | A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to ins... |
| CVE-2017-6484 | MEDIUM | 6.1 | 0.7% | Mar 5, 2017 | Multiple Cross-Site Scripting (XSS) issues were discovered in INTER-Mediator 5.5. The vulnerabilities exist due to insuf... |
| CVE-2017-6483 | — | — | 0.7% | Mar 5, 2017 | Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficien... |
| CVE-2017-6482 | — | — | — | Mar 5, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-6394. Reason: This candidate is a duplicate of... |
| CVE-2017-6481 | — | — | 0.7% | Mar 5, 2017 | Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient... |
| CVE-2017-6480 | — | — | 0.9% | Mar 5, 2017 | groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter). |
| CVE-2017-6479 | — | — | 0.7% | Mar 5, 2017 | FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic ... |
| CVE-2017-6478 | MEDIUM | 6.1 | 2.6% | Mar 5, 2017 | paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter). |
| CVE-2017-6445 | — | — | 1.0% | Mar 5, 2017 | The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encr... |
| CVE-2017-6474 | — | — | 2.9% | Mar 4, 2017 | In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malforme... |
| CVE-2017-6473 | — | — | 2.7% | Mar 4, 2017 | In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a malformed capture file... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now