2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-7843When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprin...
CVE-2017-7842If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" e...
CVE-2017-7840JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved b...
CVE-2017-7839Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be i...
CVE-2017-7838Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-doma...
CVE-2017-7837SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerabili...
CVE-2017-7836The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attac...
CVE-2017-7835Mixed content blocking of insecure (HTTP) sub-resources in a secure (HTTPS) document was not correctly applied for resou...
CVE-2017-7834A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for b...
CVE-2017-7833Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-...
CVE-2017-7832The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or...
CVE-2017-7831A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_expose...
CVE-2017-7830The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation...
CVE-2017-7829It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The r...
CVE-2017-7828A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been free...
CVE-2017-7827Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2017-7826Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corrup...
CVE-2017-7825Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of a...
CVE-2017-7824A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. T...
CVE-2017-7823The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to beh...
CVE-2017-7822The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NI...
CVE-2017-7821A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can ...
CVE-2017-7820The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or a...
CVE-2017-7819A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the ...
CVE-2017-7818A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elemen...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now