14,642 vulnerabilities published in 2017
ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer ov
In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhd
In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Ob
sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the
lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWS
Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and c
The Backup and Restore feature in Mobotap Dolphin Browser for Android 12.0.2 suffers from an arbitrary file write vulner
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection.
A Trusted RFC connection in SAP KERNEL 32NUC, SAP KERNEL 32Unicode, SAP KERNEL 64NUC, SAP KERNEL 64Unicode 7.21, 7.21EXT
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests a
The tibbr user profiles components of tibbr Community, and tibbr Enterprise expose a weakness in an improperly sandboxed
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. T
In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/cent
KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, w
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment va
boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variab
etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environm
scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the prog
libsylph/utils.c in Sylpheed through 3.6 does not validate strings before launching the program specified by the BROWSER
swt/motif/browser.c in White_dune (aka whitedune) 0.30.10 does not validate strings before launching the program specifi
batteriesConfig.mlp in OCaml Batteries Included (aka ocaml-batteries) 2.6 does not validate strings before launching the
tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER enviro
uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER e
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSE
library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWS
guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by th
Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSE
delphi_gui/WWWBrowserRunnerDM.pas in PasDoc 0.14 does not validate strings before launching the program specified by the
backends/platform/sdl/posix/posix.cpp in ScummVM 1.9.0 does not validate strings before launching the program specified
af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings before launching the program specified by the BRO
common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environm
gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environmen
examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the
default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment v
uiutil.c in Mensis 0.0.080507 does not validate strings before launching the program specified by the BROWSER environmen
lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER en
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated A
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and p
In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in th
Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter.
An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Ma
The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to
Multiple D-Link devices including the DIR-850L firmware versions 1.14B07 and 2.07.B05 contain a stack-based buffer overf
The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows d
DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user c
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 al
A Session Fixation Vulnerability exists in the MT4 Networks SenhaSegura Web Application 2.2.23.8 via login_if.php.
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started