2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5470 | — | — | 2.6% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corrup... |
| CVE-2017-5469 | — | — | 4.7% | Jun 11, 2018 | Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affect... |
| CVE-2017-5468 | — | — | 2.5% | Jun 11, 2018 | An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can resul... |
| CVE-2017-5467 | — | — | 2.5% | Jun 11, 2018 | A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping... |
| CVE-2017-5466 | — | — | 1.6% | Jun 11, 2018 | If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, trigger... |
| CVE-2017-5465 | — | — | 18.9% | Jun 11, 2018 | An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for other... |
| CVE-2017-5464 | — | — | 2.6% | Jun 11, 2018 | During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessib... |
| CVE-2017-5463 | — | — | 1.5% | Jun 11, 2018 | Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attac... |
| CVE-2017-5462 | — | — | 2.6% | Jun 11, 2018 | A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not ... |
| CVE-2017-5460 | — | — | 3.1% | Jun 11, 2018 | A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses... |
| CVE-2017-5459 | — | — | 4.7% | Jun 11, 2018 | A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability ... |
| CVE-2017-5458 | — | — | 1.4% | Jun 11, 2018 | When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This... |
| CVE-2017-5456 | — | — | 2.8% | Jun 11, 2018 | A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an... |
| CVE-2017-5455 | — | — | 3.6% | Jun 11, 2018 | The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege ... |
| CVE-2017-5454 | — | — | 2.5% | Jun 11, 2018 | A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files tha... |
| CVE-2017-5453 | — | — | 1.1% | Jun 11, 2018 | A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL par... |
| CVE-2017-5452 | — | — | 1.2% | Jun 11, 2018 | Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled ou... |
| CVE-2017-5451 | — | — | 1.5% | Jun 11, 2018 | A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event cou... |
| CVE-2017-5450 | — | — | 1.9% | Jun 11, 2018 | A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base doma... |
| CVE-2017-5449 | — | — | 2.6% | Jun 11, 2018 | A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS ... |
| CVE-2017-5448 | — | — | 2.1% | Jun 11, 2018 | An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecry... |
| CVE-2017-5447 | — | — | 17.7% | Jun 11, 2018 | An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitabl... |
| CVE-2017-5446 | — | — | 3.1% | Jun 11, 2018 | An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads... |
| CVE-2017-5445 | — | — | 2.7% | Jun 11, 2018 | A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to crea... |
| CVE-2017-5444 | — | — | 7.1% | Jun 11, 2018 | A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains im... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now