Show filters
492 Total Results
Displaying 91-100 of 492
Sort by:
Attacker Value
Unknown
CVE-2018-5099
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5129
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
0
Attacker Value
Unknown
CVE-2018-5140
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This could allow for information leakage of which applications are associated with specific MIME types by a malicious page. This vulnerability affects Firefox < 59.
0
Attacker Value
Unknown
CVE-2018-5136
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vulnerability affects Firefox < 59.
0
Attacker Value
Unknown
CVE-2018-5145
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
0
Attacker Value
Unknown
CVE-2018-5131
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a website being accessible to users if they share a common profile while browsing. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
0
Attacker Value
Unknown
CVE-2018-5101
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5108
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5094
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collection on memory that is now uninitialized. This results in a potentially exploitable crash. This vulnerability affects Firefox < 58.
0
Attacker Value
Unknown
CVE-2018-5098
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
0