CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-7751

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

    Published: 14 Jun 2017
    9.8
    Critical

    CVE-2017-7750

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability during video control operations when a "<track>" element holds a reference to an older window if that window has been replaced in the DOM. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

    Published: 14 Jun 2017
    9.8
    Critical

    CVE-2017-7749

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

    Published: 14 Jun 2017
    9.8
    Critical

    CVE-2017-5472

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no longer exists. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

    Published: 14 Jun 2017
    9.8
    Critical

    CVE-2017-5470

    Last Modified: 25 Nov 2025

    Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

    Published: 14 Jun 2017
    5.3
    Medium

    CVE-2017-9502

    Last Modified: 20 Apr 2025

    In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FILE or a file: URL lacks two slashes, the given "URL" starts with a drive letter, and libcurl is built for Windows or DOS, then libcurl would copy the path 7 bytes off, so that the end of the given path would write beyond the malloc buffer (7 bytes being the length in bytes of the ascii string "file://").

    Published: 14 Jun 2017
    7.5
    High

    CVE-2017-9233

    Last Modified: 20 Apr 2025

    XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.

    Published: 14 Jun 2017
    7.8
    High

    CVE-2017-11572

    Last Modified: 20 Apr 2025

    FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted otf file.

    Published: 14 Jun 2017
    8.8
    High

    CVE-2017-7772

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

    Published: 14 Jun 2017
    7.8
    High

    CVE-2017-11568

    Last Modified: 20 Apr 2025

    FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafted otf file.

    Published: 14 Jun 2017
    7.8
    High

    CVE-2017-11570

    Last Modified: 20 Apr 2025

    FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.

    Published: 14 Jun 2017
    7.8
    High

    CVE-2017-11571

    Last Modified: 20 Apr 2025

    FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.

    Published: 14 Jun 2017
    7.8
    High

    CVE-2017-11574

    Last Modified: 20 Apr 2025

    FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted otf file.

    Published: 14 Jun 2017
    7.8
    High

    CVE-2017-11575

    Last Modified: 20 Apr 2025

    FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a call from the readttfcopyrights function in parsettf.c.

    Published: 14 Jun 2017
    5.5
    Medium

    CVE-2017-11576

    Last Modified: 20 Apr 2025

    FontForge 20161012 does not ensure a positive size in a weight vector memcpy call in readcfftopdict (parsettf.c) resulting in DoS via a crafted otf file.

    Published: 14 Jun 2017
    7.8
    High

    CVE-2017-11577

    Last Modified: 20 Apr 2025

    FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.

    Published: 14 Jun 2017
    4.1
    Medium

    CVE-2017-12164

    Last Modified: 21 Nov 2024

    A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.

    Published: 14 Jun 2017
    3.7
    Low

    CVE-2017-3140

    Last Modified: 21 Nov 2024

    If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.

    Published: 14 Jun 2017
    7.2
    High

    CVE-2017-3141

    Last Modified: 21 Nov 2024

    The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BIND 9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S1.

    Published: 14 Jun 2017
    8.8
    High

    CVE-2017-7773

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.

    Published: 14 Jun 2017
    8.8
    High

    CVE-2017-7777

    Last Modified: 21 Nov 2024

    Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.

    Published: 14 Jun 2017
    8.8
    High

    CVE-2017-7752

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

    Published: 14 Jun 2017
    9.8
    Critical

    CVE-2017-7757

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

    Published: 14 Jun 2017
    9.1
    Critical

    CVE-2017-7758

    Last Modified: 25 Nov 2025

    An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

    Published: 14 Jun 2017
    8.1
    High

    CVE-2017-7771

    Last Modified: 21 Nov 2024

    Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.

    Published: 14 Jun 2017
    9.1
    Critical

    CVE-2017-7774

    Last Modified: 21 Nov 2024

    Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

    Published: 14 Jun 2017
    3.7
    Low

    CVE-2017-7775

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Jun 2017
    8.1
    High

    CVE-2017-7776

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.

    Published: 14 Jun 2017
    5.5
    Medium

    CVE-2017-9782

    Last Modified: 20 Apr 2025

    JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c.

    Published: 14 Jun 2017
    7.8
    High

    CVE-2017-11569

    Last Modified: 20 Apr 2025

    FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.

    Published: 14 Jun 2017
    7.8
    High

    CVE-2017-11573

    Last Modified: 20 Apr 2025

    FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted otf file.

    Published: 14 Jun 2017
    7.8
    High

    CVE-2014-9962

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2014-9963

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in WideVine DRM.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2014-9964

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in debug functionality.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2014-9965

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of an SCM call.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2015-9023

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API.

    Published: 13 Jun 2017
    7.1
    High

    CVE-2016-10339

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore.

    Published: 13 Jun 2017
    3.3
    Low

    CVE-2015-9032

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2015-9033

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2014-9960

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2015-9024

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2016-10338

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-7367

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, an integer underflow vulnerability exists while processing the boot image.

    Published: 13 Jun 2017
    7
    High

    CVE-2017-7368

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2017-8235

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a memory structure in a camera driver is not properly protected.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-8236

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an IPA driver.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2017-8239

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, userspace-controlled parameters for flash initialization are not sanitized potentially leading to exposure of kernel memory.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2014-9961

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write protection.

    Published: 13 Jun 2017
    7
    High

    CVE-2014-9966

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists in Secure Display.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2014-9967

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.

    Published: 13 Jun 2017