LiveActive security incident?Get immediate response
CVE archive

June 2017

Browse CVE records published in June 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1499 matching CVEs · Page 25 of 30.

Unknown · CVSS Not scored

CVE-2017-5462: A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal stat...

A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5465: An out-of-bounds read while processing SVG content in "ConvolvePixel".

An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5471: Memory safety bugs were reported in Firefox 53.

Memory safety bugs were reported in Firefox 53. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 54.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5430: Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52.

Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5454: A mechanism to bypass file system access protections in the sandbox to use the file picker to access differ...

A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5470: Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1.

Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5436: An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font.

An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5429: Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52.

Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5428: An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest.

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5433: A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an...

A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5417: When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible t...

When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the addressbar so that the displayed location following navigation does not match the URL of the newly loaded page. This allows for spoofing attacks. This vulnerability affects Firefox < 52.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5426: On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sand...

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox. Note: this issue only affects Linux. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5448: An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content.

An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5463: Android intents can be used to launch Firefox for Android in reader mode with a user specified URL.

Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of the addressbar as displayed to users. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5444: A buffer overflow vulnerability while parsing "application/http-index-format" format content when the heade...

A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5440: A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during...

A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5425: The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions.

The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. This has been updated to not allow access to "/private/var" and its subdirectories. Note: this issue only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5445: A vulnerability while parsing "application/http-index-format" format content where uninitialized values are...

A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5427: A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation...

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5397: The cache directory on the local file system is set to be world writable.

The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the file system to replace files used by Firefox with their own versions. This vulnerability affects Firefox < 51.0.3.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5411: A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for Web...

A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This issue is in "libGLES", which is only in use on Windows. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5409: The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by pas...

The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 45.8 and Firefox < 52.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5241: Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persiste...

Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in the "Name" and "Description" fields of a Workspace, as well as the "Description" field of a File Details pane of a file stored in a Workspace. This issue has been resolved in version 5.1.1025.

Published Jun 28, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5398: Memory safety bugs were reported in Thunderbird 45.7.

Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

Published Jun 11, 2018 · Updated Aug 5, 2024