Show filters
492 Total Results
Displaying 61-70 of 492
Sort by:
Attacker Value
Unknown

CVE-2018-5128

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in a potentially exploitable crash. This vulnerability affects Firefox < 59.
0
Attacker Value
Unknown

CVE-2018-5167

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Additionally, the JavaScript debugger will display "javascript:" links, which users could be tricked into clicking by malicious sites. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5164

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5115

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the originating site of the authentication request and may cause users to mistakenly send private credential information to a third party site. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5111

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5152

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password during login to Firefox Accounts. This issue does not expose synchronization traffic directly and is limited to the process of user login to the website and the data displayed to the user once logged in. This vulnerability affects Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5116

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown

CVE-2018-5159

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
0
Attacker Value
Unknown

CVE-2018-5157

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
0
Attacker Value
Unknown

CVE-2018-5176

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains malicious JavaScript script embedded as "javascript:" links, users may be tricked into clicking and running this code in the context of the JSON Viewer. This can allow for the theft of cookies and authorization tokens which are accessible to that context. This vulnerability affects Firefox < 60.
0