2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7817 | — | — | 1.2% | Jun 11, 2018 | A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake ad... |
| CVE-2017-7816 | — | — | 1.3% | Jun 11, 2018 | WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security che... |
| CVE-2017-7815 | — | — | 1.2% | Jun 11, 2018 | On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will ha... |
| CVE-2017-7814 | — | — | 1.2% | Jun 11, 2018 | File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing an... |
| CVE-2017-7813 | — | — | 1.6% | Jun 11, 2018 | Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer be... |
| CVE-2017-7812 | — | — | 1.3% | Jun 11, 2018 | If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that other... |
| CVE-2017-7811 | — | — | 2.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2017-7810 | — | — | 2.8% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corrup... |
| CVE-2017-7809 | — | — | 2.7% | Jun 11, 2018 | A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while stil... |
| CVE-2017-7808 | — | — | 0.9% | Jun 11, 2018 | A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against... |
| CVE-2017-7807 | — | — | 2.1% | Jun 11, 2018 | A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the do... |
| CVE-2017-7806 | — | — | 2.0% | Jun 11, 2018 | A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, ... |
| CVE-2017-7805 | — | — | 3.2% | Jun 11, 2018 | During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for la... |
| CVE-2017-7804 | — | — | 1.5% | Jun 11, 2018 | The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with ano... |
| CVE-2017-7803 | — | — | 2.0% | Jun 11, 2018 | When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This re... |
| CVE-2017-7802 | — | — | 2.7% | Jun 11, 2018 | A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these... |
| CVE-2017-7801 | — | — | 2.7% | Jun 11, 2018 | A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where ... |
| CVE-2017-7800 | — | — | 3.0% | Jun 11, 2018 | A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the discon... |
| CVE-2017-7799 | — | — | 1.4% | Jun 11, 2018 | JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supp... |
| CVE-2017-7798 | — | — | 2.1% | Jun 11, 2018 | The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page sour... |
| CVE-2017-7797 | — | — | 0.8% | Jun 11, 2018 | Response header name interning does not have same-origin protections and these headers are stored in a global registry. ... |
| CVE-2017-7796 | — | — | 0.3% | Jun 11, 2018 | On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write... |
| CVE-2017-7794 | — | — | 0.3% | Jun 11, 2018 | On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though... |
| CVE-2017-7793 | — | — | 2.3% | Jun 11, 2018 | A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still ... |
| CVE-2017-7792 | — | — | 3.3% | Jun 11, 2018 | A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely l... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now