Vulnerabilities
Tracked app vulnerabilities
7,756 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,756
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2017-7757
CRITICAL 9.8
1 app
A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a pote… |
|
CVE-2017-7756
CRITICAL 9.8
1 app
A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable… |
|
CVE-2017-7755
HIGH 7.8
1 app
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged e… |
|
CVE-2017-7754
HIGH 7.5
1 app
An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52… |
|
CVE-2017-7753
CRITICAL 9.1
1 app
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbir… |
|
CVE-2017-7752
HIGH 8.8
1 app
A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This resul… |
|
CVE-2017-7751
CRITICAL 9.8
1 app
A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox … |
|
CVE-2017-7750
CRITICAL 9.8
1 app
A use-after-free vulnerability during video control operations when a "<track>" element holds a reference to an older window if that window has been replaced i… |
|
CVE-2017-7749
CRITICAL 9.8
1 app
A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerabil… |
|
CVE-2017-5472
CRITICAL 9.8
1 app
A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no … |
|
CVE-2017-5470
CRITICAL 9.8
1 app
Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough ef… |
|
CVE-2017-5469
CRITICAL 9.8
1 app
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.… |
|
CVE-2017-5467
HIGH 7.5
1 app
A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thu… |
|
CVE-2017-5466
MEDIUM 6.1
1 app
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "dat… |
|
CVE-2017-5465
CRITICAL 9.1
1 app
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied i… |
|
CVE-2017-5464
CRITICAL 9.8
1 app
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruptio… |
|
CVE-2017-5462
MEDIUM 5.3
1 app
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS libr… |
|
CVE-2017-5460
CRITICAL 9.8
1 app
A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potential… |
|
CVE-2017-5459
CRITICAL 9.8
1 app
A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR… |
|
CVE-2017-5454
HIGH 7.5
1 app
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker thr… |
|
CVE-2017-5451
MEDIUM 4.3
1 app
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text dis… |
|
CVE-2017-5449
HIGH 7.5
1 app
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerability affects … |
|
CVE-2017-5447
CRITICAL 9.1
1 app
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to … |
|
CVE-2017-5446
CRITICAL 9.8
1 app
An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. Th… |
|
CVE-2017-5445
HIGH 7.5
1 app
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the readi… |
|
CVE-2017-5444
HIGH 7.5
1 app
A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows fo… |
|
CVE-2017-5443
CRITICAL 9.8
1 app
An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9… |
|
CVE-2017-5442
CRITICAL 9.8
1 app
A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exploitable crash. This vulnerability affe… |
|
CVE-2017-5441
CRITICAL 9.8
1 app
A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affects Thund… |
|
CVE-2017-5440
CRITICAL 9.8
1 app
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objec… |
|
CVE-2017-5439
CRITICAL 9.8
1 app
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulner… |
|
CVE-2017-5438
CRITICAL 9.8
1 app
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially ex… |
|
CVE-2017-5436
HIGH 8.8
1 app
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issu… |
|
CVE-2017-5435
CRITICAL 9.8
1 app
A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially exploitable cr… |
|
CVE-2017-5434
CRITICAL 9.8
1 app
A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thunderbird … |
|
CVE-2017-5433
CRITICAL 9.8
1 app
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller whi… |
|
CVE-2017-5432
CRITICAL 9.8
1 app
A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Thunderbird … |
|
CVE-2017-5430
CRITICAL 9.8
1 app
Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that… |
|
CVE-2017-5429
CRITICAL 9.8
1 app
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption a… |
|
CVE-2017-5426
MEDIUM 5.3
1 app
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and … |
|
CVE-2017-5425
HIGH 7.5
1 app
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subd… |
|
CVE-2017-5422
HIGH 7.5
1 app
If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink i… |
|
CVE-2017-5421
HIGH 7.5
1 app
A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what site is currently loade… |
|
CVE-2017-5419
HIGH 7.5
1 app
If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-responsive, requiring shutdown through the ope… |
|
CVE-2017-5418
MEDIUM 5.3
1 app
An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of random memory… |
|
CVE-2017-5416
HIGH 7.5
1 app
In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vulnerability … |
|
CVE-2017-5414
MEDIUM 5.5
1 app
The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disc… |
|
CVE-2017-5413
CRITICAL 9.8
1 app
A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52. |
|
CVE-2017-5412
HIGH 7.5
1 app
A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird < 52. |
|
CVE-2017-5411
HIGH 7.5
1 app
A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while st… |