2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-7791On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary ...
CVE-2017-7790On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, s...
CVE-2017-7789If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid ...
CVE-2017-7788When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit th...
CVE-2017-7787Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes ...
CVE-2017-7786A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a po...
CVE-2017-7785A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. Th...
CVE-2017-7784A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer h...
CVE-2017-7783If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example...
CVE-2017-7782An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, ...
CVE-2017-7781An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can ...
CVE-2017-7780Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2017-7779Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed eviden...
CVE-2017-7778A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and ...
CVE-2017-7770A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar...
CVE-2017-7768The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the loc...
CVE-2017-7767The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using...
CVE-2017-7766An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation th...
CVE-2017-7765The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Intern...
CVE-2017-7764Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the add...
CVE-2017-7763Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this ...
CVE-2017-7762When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. ...
CVE-2017-7761The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users....
CVE-2017-7760The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. T...
CVE-2017-7759Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now