Show filters
492 Total Results
Displaying 111-120 of 492
Sort by:
Attacker Value
Unknown

CVE-2018-5160

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5133

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences/in-content/preferences.xul" directly in a tab and executes a search. This stored preference is also executed whenever an EME video player plugin displays a CDM-disabled message as a notification message. This vulnerability affects Firefox < 59.
0
Attacker Value
Unknown

CVE-2018-5112

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5162

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
0
Attacker Value
Unknown

CVE-2018-5172

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5180

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited because the memory is freed and reused in a brief window of time during the freeing of the same callstack. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5178

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
0
Attacker Value
Unknown

CVE-2018-5161

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
0
Attacker Value
Unknown

CVE-2018-5091

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5113

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.
0