2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-5401A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resu...
CVE-2017-5400JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potenti...
CVE-2017-5399Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2017-5398Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we pre...
CVE-2017-5397The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from ...
CVE-2017-5396A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the m...
CVE-2017-5395Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the n...
CVE-2017-5394A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due t...
CVE-2017-5393The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessib...
CVE-2017-5392Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorre...
CVE-2017-5391Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a con...
CVE-2017-5390The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing J...
CVE-2017-5389WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions...
CVE-2017-5388A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN pac...
CVE-2017-5387The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "so...
CVE-2017-5386WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, le...
CVE-2017-5385Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy r...
CVE-2017-5384Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which...
CVE-2017-5383URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allo...
CVE-2017-5382Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for th...
CVE-2017-5381The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certif...
CVE-2017-5380A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thun...
CVE-2017-5379Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulner...
CVE-2017-5378Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address c...
CVE-2017-5377A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potenti...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now