2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5414 | — | — | 0.3% | Jun 11, 2018 | The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating sys... |
| CVE-2017-5413 | — | — | 1.9% | Jun 11, 2018 | A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and ... |
| CVE-2017-5412 | — | — | 4.6% | Jun 11, 2018 | A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects ... |
| CVE-2017-5411 | — | — | 1.8% | Jun 11, 2018 | A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. T... |
| CVE-2017-5410 | — | — | 3.4% | Jun 11, 2018 | Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how... |
| CVE-2017-5409 | — | — | 0.4% | Jun 11, 2018 | The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a specia... |
| CVE-2017-5408 | — | — | 2.6% | Jun 11, 2018 | Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-o... |
| CVE-2017-5407 | — | — | 2.8% | Jun 11, 2018 | Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pi... |
| CVE-2017-5406 | — | — | 1.8% | Jun 11, 2018 | A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip i... |
| CVE-2017-5405 | — | — | 2.6% | Jun 11, 2018 | Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. Thi... |
| CVE-2017-5404 | — | — | 17.5% | Jun 11, 2018 | A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and... |
| CVE-2017-5403 | — | — | 1.7% | Jun 11, 2018 | When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root obje... |
| CVE-2017-5402 | — | — | 2.9% | Jun 11, 2018 | A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroye... |
| CVE-2017-5401 | — | — | 3.1% | Jun 11, 2018 | A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resu... |
| CVE-2017-5400 | — | — | 3.6% | Jun 11, 2018 | JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potenti... |
| CVE-2017-5399 | — | — | 2.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2017-5398 | — | — | 3.8% | Jun 11, 2018 | Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we pre... |
| CVE-2017-5397 | — | — | 3.2% | Jun 11, 2018 | The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from ... |
| CVE-2017-5396 | — | — | 4.1% | Jun 11, 2018 | A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the m... |
| CVE-2017-5395 | — | — | 1.2% | Jun 11, 2018 | Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the n... |
| CVE-2017-5394 | — | — | 0.8% | Jun 11, 2018 | A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due t... |
| CVE-2017-5393 | — | — | 0.9% | Jun 11, 2018 | The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessib... |
| CVE-2017-5392 | — | — | 1.8% | Jun 11, 2018 | Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorre... |
| CVE-2017-5391 | — | — | 1.8% | Jun 11, 2018 | Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a con... |
| CVE-2017-5390 | — | — | 4.0% | Jun 11, 2018 | The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing J... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now