2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2017-5414The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating sys...
CVE-2017-5413A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and ...
CVE-2017-5412A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects ...
CVE-2017-5411A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. T...
CVE-2017-5410Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how...
CVE-2017-5409The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a specia...
CVE-2017-5408Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-o...
CVE-2017-5407Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pi...
CVE-2017-5406A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip i...
CVE-2017-5405Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. Thi...
CVE-2017-5404A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and...
CVE-2017-5403When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root obje...
CVE-2017-5402A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroye...
CVE-2017-5401A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resu...
CVE-2017-5400JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potenti...
CVE-2017-5399Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2017-5398Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we pre...
CVE-2017-5397The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from ...
CVE-2017-5396A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the m...
CVE-2017-5395Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the n...
CVE-2017-5394A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due t...
CVE-2017-5393The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessib...
CVE-2017-5392Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorre...
CVE-2017-5391Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a con...
CVE-2017-5390The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing J...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now