2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5389 | — | — | 0.9% | Jun 11, 2018 | WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions... |
| CVE-2017-5388 | — | — | 1.7% | Jun 11, 2018 | A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN pac... |
| CVE-2017-5387 | — | — | 0.4% | Jun 11, 2018 | The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "so... |
| CVE-2017-5386 | — | — | 2.3% | Jun 11, 2018 | WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, le... |
| CVE-2017-5385 | — | — | 1.7% | Jun 11, 2018 | Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy r... |
| CVE-2017-5384 | — | — | 1.5% | Jun 11, 2018 | Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which... |
| CVE-2017-5383 | — | — | 2.5% | Jun 11, 2018 | URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allo... |
| CVE-2017-5382 | — | — | 1.5% | Jun 11, 2018 | Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for th... |
| CVE-2017-5381 | — | — | 1.3% | Jun 11, 2018 | The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certif... |
| CVE-2017-5380 | — | — | 3.2% | Jun 11, 2018 | A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thun... |
| CVE-2017-5379 | — | — | 1.8% | Jun 11, 2018 | Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulner... |
| CVE-2017-5378 | — | — | 3.4% | Jun 11, 2018 | Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address c... |
| CVE-2017-5377 | — | — | 1.7% | Jun 11, 2018 | A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potenti... |
| CVE-2017-5376 | — | — | 3.2% | Jun 11, 2018 | Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45... |
| CVE-2017-5375 | — | — | 33.4% | Jun 11, 2018 | JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T... |
| CVE-2017-5374 | — | — | 1.8% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume... |
| CVE-2017-5373 | — | — | 3.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corr... |
| CVE-2017-3208 | — | — | 4.0% | Jun 11, 2018 | The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows extern... |
| CVE-2017-3207 | — | — | 8.2% | Jun 11, 2018 | The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class inst... |
| CVE-2017-3206 | — | — | 3.7% | Jun 11, 2018 | The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external ... |
| CVE-2017-3203 | — | — | 6.3% | Jun 11, 2018 | The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externa... |
| CVE-2017-3202 | — | — | 8.2% | Jun 11, 2018 | The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instan... |
| CVE-2017-3201 | — | — | 5.4% | Jun 11, 2018 | The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class ins... |
| CVE-2017-6294 | — | — | 0.2% | Jun 7, 2018 | In Android before the 2018-06-05 security patch level, NVIDIA Tegra X1 TZ contains a possible out of bounds write due to... |
| CVE-2017-6292 | — | — | 0.2% | Jun 7, 2018 | In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now