Show filters
225 Total Results
Displaying 111-120 of 225
Sort by:
Attacker Value
Unknown
CVE-2018-5180
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited because the memory is freed and reused in a brief window of time during the freeing of the same callstack. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown
CVE-2018-5178
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
0
Attacker Value
Unknown
CVE-2018-5091
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5113
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5169
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the home page tabs. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown
CVE-2018-5109
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5175
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website contains an HTML injection flaw an attacker could inject a reference to a copy of the "require.js" library that is part of Firefox's Developer Tools, and then use a known technique using that library to bypass the CSP restrictions on executing injected scripts. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown
CVE-2018-5093
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5142
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown protocol" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.
0
Attacker Value
Unknown
CVE-2018-5137
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this vulnerability does not affect WebExtensions. This vulnerability affects Firefox < 59.
0