2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7830 | — | — | 2.5% | Jun 11, 2018 | The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation... |
| CVE-2017-7829 | — | — | 1.8% | Jun 11, 2018 | It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The r... |
| CVE-2017-7828 | — | — | 7.4% | Jun 11, 2018 | A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been free... |
| CVE-2017-7827 | — | — | 2.7% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2017-7826 | — | — | 3.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corrup... |
| CVE-2017-7825 | — | — | 1.6% | Jun 11, 2018 | Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of a... |
| CVE-2017-7824 | — | — | 3.6% | Jun 11, 2018 | A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. T... |
| CVE-2017-7823 | — | — | 1.5% | Jun 11, 2018 | The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to beh... |
| CVE-2017-7822 | — | — | 1.4% | Jun 11, 2018 | The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NI... |
| CVE-2017-7821 | — | — | 2.0% | Jun 11, 2018 | A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can ... |
| CVE-2017-7820 | — | — | 1.2% | Jun 11, 2018 | The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or a... |
| CVE-2017-7819 | — | — | 3.4% | Jun 11, 2018 | A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the ... |
| CVE-2017-7818 | — | — | 3.4% | Jun 11, 2018 | A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elemen... |
| CVE-2017-7817 | — | — | 1.2% | Jun 11, 2018 | A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake ad... |
| CVE-2017-7816 | — | — | 1.3% | Jun 11, 2018 | WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security che... |
| CVE-2017-7815 | — | — | 1.2% | Jun 11, 2018 | On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will ha... |
| CVE-2017-7814 | — | — | 1.2% | Jun 11, 2018 | File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing an... |
| CVE-2017-7813 | — | — | 1.6% | Jun 11, 2018 | Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer be... |
| CVE-2017-7812 | — | — | 1.3% | Jun 11, 2018 | If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that other... |
| CVE-2017-7811 | — | — | 2.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2017-7810 | — | — | 2.8% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corrup... |
| CVE-2017-7809 | — | — | 2.7% | Jun 11, 2018 | A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while stil... |
| CVE-2017-7808 | — | — | 0.9% | Jun 11, 2018 | A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against... |
| CVE-2017-7807 | — | — | 2.1% | Jun 11, 2018 | A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the do... |
| CVE-2017-7806 | — | — | 2.0% | Jun 11, 2018 | A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now