Show filters
225 Total Results
Displaying 121-130 of 225
Sort by:
Attacker Value
Unknown

CVE-2018-5092

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the main thread while cancelling fetch operations. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5100

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scripts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5132

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.
0
Attacker Value
Unknown

CVE-2018-5117

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5163

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5166

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5177

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances, leading to a buffer overflow and crash if it occurs. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5114

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5182

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local file will be opened. This is contrary to policy and is what would happen if the string were the equivalent "file:" URL. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2016-2829

Disclosure Date: June 13, 2016 (last updated November 25, 2024)
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.
0