![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-7827 – Ubuntu Security Notice USN-3477-1
https://notcve.org/view.php?id=CVE-2017-7827
17 Nov 2017 — Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57. Se han informado de errores de seguridad de memoria en Firefox 56. Algunos de estos errores mostraron evidencias de corrupción de memoria y se cree que, con el esfuerzo necesario, se podrían explotar para ejecutar código arbitrario. • http://www.securityfocus.com/bid/101832 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-7838 – Ubuntu Security Notice USN-3477-3
https://notcve.org/view.php?id=CVE-2017-7838
17 Nov 2017 — Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed in native script and the sub-domain only displaying as punycode. This could be used for limited spoofing attacks due to user confusion. This vulnerability affects Firefox < 57. El texto de formato punycode se mostrará a todos los nombres de dominio internacionales cualificados en determinadas instancias cuando u... • http://www.securityfocus.com/bid/101832 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-7840 – Ubuntu Security Notice USN-3477-3
https://notcve.org/view.php?id=CVE-2017-7840
17 Nov 2017 — JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting exported HTML file is later opened in a browser this JavaScript will be executed. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks if users were convinced to add malicious tags to bookmarks, export them, and then open the resulting file. This vulnerability affects Firefox < 57. Se puede inyectar código JavaScript en un arc... • http://www.securityfocus.com/bid/101832 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-7833 – Ubuntu Security Notice USN-3477-3
https://notcve.org/view.php?id=CVE-2017-7833
17 Nov 2017 — Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some font sets on the addressbar. The non-Latin character will not be visible to most viewers. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerability affects Firefox < 57. Algunos caracteres marcas de vocales árabes e indios se pueden combinar con caracteres latinos en un nombre de dominio para eclipsa... • http://www.securityfocus.com/bid/101832 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-7832 – Ubuntu Security Notice USN-3477-3
https://notcve.org/view.php?id=CVE-2017-7832
17 Nov 2017 — The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the addressbar by the dotless version of 'i' followed by the same accent as a second character with most font sets. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerability affects Firefox < 57. El carácter único, combinado, versión de la letra "i"con uno de los acentos potenciales en unicode, como ... • http://www.securityfocus.com/bid/101832 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-7837 – Ubuntu Security Notice USN-3477-3
https://notcve.org/view.php?id=CVE-2017-7837
17 Nov 2017 — SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox < 57. SVG cargado mediante etiquetas "" pueden utilizar etiquetas "" en los datos SVG para configurar cookies para esta página. Esta vulnerabilidad afecta a las versiones anteriores a la 57 de Firefox. USN-3477-1 fixed vulnerabilities in Firefox. • http://www.securityfocus.com/bid/101832 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-7842 – Ubuntu Security Notice USN-3477-3
https://notcve.org/view.php?id=CVE-2017-7842
17 Nov 2017 — If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "" elements instead of one. One of these requests includes the referrer instead of respecting the set policy to not include a referrer on requests. This vulnerability affects Firefox < 57. Si el atributo Referrer Policy de un documento se establece en "no-referrer", a veces se hacen dos peticiones de red para elementos "" en lugar de una. Una de estas peticiones incluye al referrer en lugar de... • http://www.securityfocus.com/bid/101832 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-7831 – Ubuntu Security Notice USN-3477-3
https://notcve.org/view.php?id=CVE-2017-7831
17 Nov 2017 — A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy objects. These properties should be explicitly unavailable to proxy objects. This vulnerability affects Firefox < 57. Una vulnerabilidad en la que el wrapper de seguridad no deniega el acceso a determinadas propiedades expuestas usando el mecanismo obsoleto "_exposedProps_" en los objetos proxy. Estas propiedades deberían no estar disponibles explícitamente para... • http://www.securityfocus.com/bid/101832 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-7834 – Ubuntu Security Notice USN-3477-3
https://notcve.org/view.php?id=CVE-2017-7834
17 Nov 2017 — A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy including the execution of JavaScript. In prior versions when "data:" documents also inherited the context of the original page this would allow for potential cross-site scripting (XSS) attacks. This vulnerability affects Firefox < 57. Una URL "data:" cargada en una nueva pestaña no hereda la política de seguridad de contenido (CSP) de la página original, permitiendo ... • http://www.securityfocus.com/bid/101832 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-7830 – Mozilla: Cross-origin URL information leak through Resource Timing API (MFSA 2017-25)
https://notcve.org/view.php?id=CVE-2017-7830
16 Nov 2017 — The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data theft of URLs loaded by users. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5. La API Resource Timing revelaba incorrectamente las navegaciones en iframes cross-origin. Esta es una violación de la política same-origin y podría permitir el robo de datos de URL cargadas por los usuarios. • http://www.securityfocus.com/bid/101832 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •