Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2017-7844
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which …
Firefox
57.0.1+
MEDIUM 6.1
CVE-2017-7834
A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy includi…
Firefox
after 56.0.2
MEDIUM 6.1
CVE-2017-7839
Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScr…
Firefox
after 56.0.2
MEDIUM 6.1
CVE-2017-7840
JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting ex…
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7831
A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy o…
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7832
The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the…
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7833
Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some fon…
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7837
SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox < 57.
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7838
Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode disp…
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7842
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One o…
Firefox
after 56.0.2
CRITICAL 9.8
CVE-2017-7811
Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…
Firefox
56.0+
CRITICAL 9.8
CVE-2017-7821
A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific…
Firefox
after 55.0.3
HIGH 8.2
CVE-2017-7813
Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually resu…
Firefox
after 55.0.3
HIGH 7.5
CVE-2017-7805
During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some case…
Firefox
Mitigation only
HIGH 7.5
CVE-2017-7806
A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially ex…
Firefox
55.0+
MEDIUM 5.3
CVE-2017-7808
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the o…
Firefox
55.0+
MEDIUM 5.3
CVE-2017-7812
If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to …
Firefox
after 55.0.3
MEDIUM 5.3
CVE-2017-7815
On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domains as th…
Firefox
after 55.0.3
MEDIUM 5.3
CVE-2017-7816
WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow this behavi…
Firefox
after 55.0.3
MEDIUM 5.3
CVE-2017-7817
A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. Th…
Firefox
after 55.0.3
MEDIUM 5.3
CVE-2017-7820
The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or an extension the web content c…
Firefox
after 55.0.3
MEDIUM 5.3
CVE-2017-7822
The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NIST Special Publication 800-38…
Firefox
after 55.0.3
CRITICAL 9.8
CVE-2017-7788
When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content S…
Firefox
55.0+
HIGH 7.8
CVE-2017-7794
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only …
Firefox
55.0+
HIGH 7.5
CVE-2017-7783EPSS 14%
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:[email protected]"), the resulting modal p…
Firefox
55.0+
HIGH 7.5
CVE-2017-7790
On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, stack memory data can be copie…
Firefox
55.0+
HIGH 7.5
CVE-2017-7797
Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header nam…
Firefox
55.0+
HIGH 7.5
CVE-2017-7804
The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write a…
Firefox
52.3.0 / 55.0+
MEDIUM 6.1
CVE-2017-7799
JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usage and is n…
Firefox
55.0+
MEDIUM 5.3
CVE-2017-7789
If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Sec…
Firefox
55.0+