2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7805 | — | — | 3.2% | Jun 11, 2018 | During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for la... |
| CVE-2017-7804 | — | — | 1.5% | Jun 11, 2018 | The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with ano... |
| CVE-2017-7803 | — | — | 2.0% | Jun 11, 2018 | When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This re... |
| CVE-2017-7802 | — | — | 2.7% | Jun 11, 2018 | A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these... |
| CVE-2017-7801 | — | — | 2.7% | Jun 11, 2018 | A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where ... |
| CVE-2017-7800 | — | — | 3.0% | Jun 11, 2018 | A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the discon... |
| CVE-2017-7799 | — | — | 1.4% | Jun 11, 2018 | JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supp... |
| CVE-2017-7798 | — | — | 2.1% | Jun 11, 2018 | The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page sour... |
| CVE-2017-7797 | — | — | 0.8% | Jun 11, 2018 | Response header name interning does not have same-origin protections and these headers are stored in a global registry. ... |
| CVE-2017-7796 | — | — | 0.3% | Jun 11, 2018 | On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write... |
| CVE-2017-7794 | — | — | 0.3% | Jun 11, 2018 | On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though... |
| CVE-2017-7793 | — | — | 2.3% | Jun 11, 2018 | A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still ... |
| CVE-2017-7792 | — | — | 3.3% | Jun 11, 2018 | A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely l... |
| CVE-2017-7791 | — | — | 1.8% | Jun 11, 2018 | On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary ... |
| CVE-2017-7790 | — | — | 1.7% | Jun 11, 2018 | On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, s... |
| CVE-2017-7789 | — | — | 1.8% | Jun 11, 2018 | If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid ... |
| CVE-2017-7788 | — | — | 2.3% | Jun 11, 2018 | When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit th... |
| CVE-2017-7787 | — | — | 2.4% | Jun 11, 2018 | Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes ... |
| CVE-2017-7786 | — | — | 4.2% | Jun 11, 2018 | A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a po... |
| CVE-2017-7785 | — | — | 4.2% | Jun 11, 2018 | A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. Th... |
| CVE-2017-7784 | — | — | 3.6% | Jun 11, 2018 | A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer h... |
| CVE-2017-7783 | — | — | 13.7% | Jun 11, 2018 | If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example... |
| CVE-2017-7782 | — | — | 1.1% | Jun 11, 2018 | An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, ... |
| CVE-2017-7781 | — | — | 2.8% | Jun 11, 2018 | An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can ... |
| CVE-2017-7780 | — | — | 1.9% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume t... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now