Show filters
492 Total Results
Displaying 131-140 of 492
Sort by:
Attacker Value
Unknown

CVE-2018-5117

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5163

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5166

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5177

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances, leading to a buffer overflow and crash if it occurs. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5114

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5182

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local file will be opened. This is contrary to policy and is what would happen if the string were the equivalent "file:" URL. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-10360

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
0
Attacker Value
Unknown

CVE-2018-12020

Disclosure Date: June 08, 2018 (last updated November 26, 2024)
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
Attacker Value
Unknown

CVE-2018-4200

Disclosure Date: June 08, 2018 (last updated November 26, 2024)
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site that triggers a WebCore::jsElementScrollHeightGetter use-after-free.
0
Attacker Value
Unknown

CVE-2018-4222

Disclosure Date: June 08, 2018 (last updated November 26, 2024)
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a getWasmBufferFromValue out-of-bounds read during WebAssembly compilation.
0