2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7791 | — | — | 1.8% | Jun 11, 2018 | On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary ... |
| CVE-2017-7790 | — | — | 1.7% | Jun 11, 2018 | On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, s... |
| CVE-2017-7789 | — | — | 1.8% | Jun 11, 2018 | If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid ... |
| CVE-2017-7788 | — | — | 2.3% | Jun 11, 2018 | When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit th... |
| CVE-2017-7787 | — | — | 2.4% | Jun 11, 2018 | Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes ... |
| CVE-2017-7786 | — | — | 4.2% | Jun 11, 2018 | A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a po... |
| CVE-2017-7785 | — | — | 4.2% | Jun 11, 2018 | A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. Th... |
| CVE-2017-7784 | — | — | 3.6% | Jun 11, 2018 | A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer h... |
| CVE-2017-7783 | — | — | 13.7% | Jun 11, 2018 | If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example... |
| CVE-2017-7782 | — | — | 1.1% | Jun 11, 2018 | An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, ... |
| CVE-2017-7781 | — | — | 2.8% | Jun 11, 2018 | An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can ... |
| CVE-2017-7780 | — | — | 1.9% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2017-7779 | — | — | 2.7% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed eviden... |
| CVE-2017-7778 | — | — | 5.2% | Jun 11, 2018 | A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and ... |
| CVE-2017-7770 | — | — | 1.1% | Jun 11, 2018 | A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar... |
| CVE-2017-7768 | — | — | 0.3% | Jun 11, 2018 | The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the loc... |
| CVE-2017-7767 | — | — | 0.3% | Jun 11, 2018 | The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using... |
| CVE-2017-7766 | — | — | 0.4% | Jun 11, 2018 | An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation th... |
| CVE-2017-7765 | — | — | 1.4% | Jun 11, 2018 | The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Intern... |
| CVE-2017-7764 | — | — | 2.0% | Jun 11, 2018 | Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the add... |
| CVE-2017-7763 | — | — | 1.1% | Jun 11, 2018 | Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this ... |
| CVE-2017-7762 | — | — | 1.9% | Jun 11, 2018 | When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. ... |
| CVE-2017-7761 | — | — | 0.3% | Jun 11, 2018 | The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users.... |
| CVE-2017-7760 | — | — | 0.4% | Jun 11, 2018 | The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. T... |
| CVE-2017-7759 | — | — | 0.7% | Jun 11, 2018 | Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now