2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7843 | — | — | 3.0% | Jun 11, 2018 | When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprin... |
| CVE-2017-7842 | — | — | 1.6% | Jun 11, 2018 | If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" e... |
| CVE-2017-7840 | — | — | 1.1% | Jun 11, 2018 | JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved b... |
| CVE-2017-7839 | — | — | 1.1% | Jun 11, 2018 | Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be i... |
| CVE-2017-7838 | — | — | 1.5% | Jun 11, 2018 | Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-doma... |
| CVE-2017-7837 | — | — | 1.5% | Jun 11, 2018 | SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerabili... |
| CVE-2017-7836 | — | — | 0.3% | Jun 11, 2018 | The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attac... |
| CVE-2017-7835 | — | — | 1.5% | Jun 11, 2018 | Mixed content blocking of insecure (HTTP) sub-resources in a secure (HTTPS) document was not correctly applied for resou... |
| CVE-2017-7834 | — | — | 1.5% | Jun 11, 2018 | A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for b... |
| CVE-2017-7833 | — | — | 1.5% | Jun 11, 2018 | Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-... |
| CVE-2017-7832 | — | — | 1.5% | Jun 11, 2018 | The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or... |
| CVE-2017-7831 | — | — | 1.6% | Jun 11, 2018 | A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_expose... |
| CVE-2017-7830 | — | — | 2.5% | Jun 11, 2018 | The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation... |
| CVE-2017-7829 | — | — | 1.8% | Jun 11, 2018 | It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The r... |
| CVE-2017-7828 | — | — | 7.4% | Jun 11, 2018 | A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been free... |
| CVE-2017-7827 | — | — | 2.7% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2017-7826 | — | — | 3.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corrup... |
| CVE-2017-7825 | — | — | 1.6% | Jun 11, 2018 | Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of a... |
| CVE-2017-7824 | — | — | 3.6% | Jun 11, 2018 | A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. T... |
| CVE-2017-7823 | — | — | 1.5% | Jun 11, 2018 | The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to beh... |
| CVE-2017-7822 | — | — | 1.4% | Jun 11, 2018 | The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NI... |
| CVE-2017-7821 | — | — | 2.0% | Jun 11, 2018 | A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can ... |
| CVE-2017-7820 | — | — | 1.2% | Jun 11, 2018 | The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or a... |
| CVE-2017-7819 | — | — | 3.4% | Jun 11, 2018 | A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the ... |
| CVE-2017-7818 | — | — | 3.4% | Jun 11, 2018 | A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elemen... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now