Show filters
147 Total Results
Displaying 51-60 of 147
Sort by:
Attacker Value
Unknown

CVE-2018-18497

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.
0
Attacker Value
Unknown

CVE-2018-18492

Disclosure Date: February 28, 2019 (last updated December 06, 2023)
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
0
Attacker Value
Unknown

CVE-2018-12406

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 64.
0
Attacker Value
Unknown

CVE-2018-12389

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.3 and Thunderbird < 60.3.
0
Attacker Value
Unknown

CVE-2018-12401

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63.
0
Attacker Value
Unknown

CVE-2018-12388

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63.
0
Attacker Value
Unknown

CVE-2018-12392

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
0
Attacker Value
Unknown

CVE-2018-12397

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
0
Attacker Value
Unknown

CVE-2018-12398

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.
0
Attacker Value
Unknown

CVE-2018-12390

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
0