2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-5428An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability di...
CVE-2017-5427A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If...
CVE-2017-5426On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is starte...
CVE-2017-5425The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matc...
CVE-2017-5422If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploit...
CVE-2017-5421A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user co...
CVE-2017-5420A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressba...
CVE-2017-5419If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-respons...
CVE-2017-5418An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leaka...
CVE-2017-5417When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the ...
CVE-2017-5416In certain circumstances a networking event listener can be prematurely released. This appears to result in a null deref...
CVE-2017-5415An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leadin...
CVE-2017-5414The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating sys...
CVE-2017-5413A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and ...
CVE-2017-5412A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects ...
CVE-2017-5411A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. T...
CVE-2017-5410Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how...
CVE-2017-5409The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a specia...
CVE-2017-5408Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-o...
CVE-2017-5407Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pi...
CVE-2017-5406A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip i...
CVE-2017-5405Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. Thi...
CVE-2017-5404A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and...
CVE-2017-5403When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root obje...
CVE-2017-5402A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroye...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now