CVE-2018-5168
- EPSS 1.03%
- Published 11.06.2018 21:29:15
- Last modified 21.11.2024 04:08:15
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or ...
CVE-2018-5170
- EPSS 0.88%
- Published 11.06.2018 21:29:15
- Last modified 21.11.2024 04:08:15
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and ...
CVE-2018-5129
- EPSS 2.44%
- Published 11.06.2018 21:29:14
- Last modified 21.11.2024 04:08:10
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunde...
CVE-2018-5130
- EPSS 1.22%
- Published 11.06.2018 21:29:14
- Last modified 21.11.2024 04:08:10
When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
CVE-2018-5131
- EPSS 1.48%
- Published 11.06.2018 21:29:14
- Last modified 21.11.2024 04:08:10
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored...
CVE-2018-5144
- EPSS 5.99%
- Published 11.06.2018 21:29:14
- Last modified 21.11.2024 04:08:12
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
CVE-2018-5145
- EPSS 4.12%
- Published 11.06.2018 21:29:14
- Last modified 21.11.2024 04:08:12
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 an...
CVE-2018-5146
- EPSS 29.45%
- Published 11.06.2018 21:29:14
- Last modified 21.11.2024 04:08:12
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
CVE-2018-5148
- EPSS 1.68%
- Published 11.06.2018 21:29:14
- Last modified 21.11.2024 04:08:12
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52....
CVE-2018-5150
- EPSS 4.12%
- Published 11.06.2018 21:29:14
- Last modified 21.11.2024 04:08:12
Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This v...