2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-5455The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege ...
CVE-2017-5454A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files tha...
CVE-2017-5453A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL par...
CVE-2017-5452Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled ou...
CVE-2017-5451A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event cou...
CVE-2017-5450A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base doma...
CVE-2017-5449A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS ...
CVE-2017-5448An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecry...
CVE-2017-5447An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitabl...
CVE-2017-5446An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads...
CVE-2017-5445A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to crea...
CVE-2017-5444A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains im...
CVE-2017-5443An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects...
CVE-2017-5442A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exp...
CVE-2017-5441A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable ...
CVE-2017-5440A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching whi...
CVE-2017-5439A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a pot...
CVE-2017-5438A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during han...
CVE-2017-5436An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a p...
CVE-2017-5435A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This ...
CVE-2017-5434A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. ...
CVE-2017-5433A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dr...
CVE-2017-5432A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. ...
CVE-2017-5430Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence o...
CVE-2017-5429Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now