Show filters
492 Total Results
Displaying 121-130 of 492
Sort by:
Attacker Value
Unknown
CVE-2017-7829
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.
0
Attacker Value
Unknown
CVE-2018-5169
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the home page tabs. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown
CVE-2018-5109
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5175
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website contains an HTML injection flaw an attacker could inject a reference to a copy of the "require.js" library that is part of Firefox's Developer Tools, and then use a known technique using that library to bypass the CSP restrictions on executing injected scripts. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown
CVE-2018-5093
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5142
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown protocol" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.
0
Attacker Value
Unknown
CVE-2018-5137
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this vulnerability does not affect WebExtensions. This vulnerability affects Firefox < 59.
0
Attacker Value
Unknown
CVE-2018-5092
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the main thread while cancelling fetch operations. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5100
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scripts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5132
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.
0