7.8
CVE-2018-5105
- EPSS 0.42%
- Veröffentlicht 11.06.2018 21:29:13
- Zuletzt bearbeitet 21.11.2024 04:08:06
- Erkennungen
WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent. This vulnerability affects Firefox < 58.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.337 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
http://www.securitytracker.com/id/1040270
https://usn.ubuntu.com/3544-1/
https://www.mozilla.org/security/advisories/mfsa2018-02/
http://www.securityfocus.com/bid/102786
https://bugzilla.mozilla.org/show_bug.cgi?id=1390882