2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2017-5470Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corrup...
CVE-2017-5469Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affect...
CVE-2017-5468An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can resul...
CVE-2017-5467A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping...
CVE-2017-5466If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, trigger...
CVE-2017-5465An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for other...
CVE-2017-5464During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessib...
CVE-2017-5463Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attac...
CVE-2017-5462A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not ...
CVE-2017-5460A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses...
CVE-2017-5459A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability ...
CVE-2017-5458When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This...
CVE-2017-5456A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an...
CVE-2017-5455The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege ...
CVE-2017-5454A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files tha...
CVE-2017-5453A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL par...
CVE-2017-5452Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled ou...
CVE-2017-5451A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event cou...
CVE-2017-5450A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base doma...
CVE-2017-5449A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS ...
CVE-2017-5448An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecry...
CVE-2017-5447An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitabl...
CVE-2017-5446An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads...
CVE-2017-5445A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to crea...
CVE-2017-5444A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains im...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now