2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5443 | — | — | 3.1% | Jun 11, 2018 | An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects... |
| CVE-2017-5442 | — | — | 2.7% | Jun 11, 2018 | A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exp... |
| CVE-2017-5441 | — | — | 3.1% | Jun 11, 2018 | A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable ... |
| CVE-2017-5440 | — | — | 3.1% | Jun 11, 2018 | A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching whi... |
| CVE-2017-5439 | — | — | 3.7% | Jun 11, 2018 | A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a pot... |
| CVE-2017-5438 | — | — | 3.7% | Jun 11, 2018 | A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during han... |
| CVE-2017-5436 | — | — | 2.4% | Jun 11, 2018 | An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a p... |
| CVE-2017-5435 | — | — | 3.2% | Jun 11, 2018 | A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This ... |
| CVE-2017-5434 | — | — | 3.7% | Jun 11, 2018 | A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. ... |
| CVE-2017-5433 | — | — | 3.7% | Jun 11, 2018 | A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dr... |
| CVE-2017-5432 | — | — | 3.2% | Jun 11, 2018 | A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. ... |
| CVE-2017-5430 | — | — | 3.0% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence o... |
| CVE-2017-5429 | — | — | 3.5% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs... |
| CVE-2017-5428 | — | — | 2.8% | Jun 11, 2018 | An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability di... |
| CVE-2017-5427 | — | — | 0.2% | Jun 11, 2018 | A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If... |
| CVE-2017-5426 | — | — | 1.4% | Jun 11, 2018 | On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is starte... |
| CVE-2017-5425 | — | — | 2.0% | Jun 11, 2018 | The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matc... |
| CVE-2017-5422 | — | — | 2.4% | Jun 11, 2018 | If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploit... |
| CVE-2017-5421 | — | — | 1.9% | Jun 11, 2018 | A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user co... |
| CVE-2017-5420 | — | — | 1.3% | Jun 11, 2018 | A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressba... |
| CVE-2017-5419 | — | — | 2.4% | Jun 11, 2018 | If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-respons... |
| CVE-2017-5418 | — | — | 1.3% | Jun 11, 2018 | An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leaka... |
| CVE-2017-5417 | — | — | 1.1% | Jun 11, 2018 | When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the ... |
| CVE-2017-5416 | — | — | 1.8% | Jun 11, 2018 | In certain circumstances a networking event listener can be prematurely released. This appears to result in a null deref... |
| CVE-2017-5415 | — | — | 12.6% | Jun 11, 2018 | An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leadin... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now