CVE-2018-5117
- EPSS 2.15%
- Published 11.06.2018 21:29:13
- Last modified 21.11.2024 04:08:08
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can misle...
CVE-2018-5127
- EPSS 20.99%
- Published 11.06.2018 21:29:13
- Last modified 21.11.2024 04:08:09
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
CVE-2017-7846
- EPSS 1.35%
- Published 11.06.2018 21:29:12
- Last modified 21.11.2024 03:32:47
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird...
CVE-2017-7848
- EPSS 1.89%
- Published 11.06.2018 21:29:12
- Last modified 21.11.2024 03:32:47
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
CVE-2018-5091
- EPSS 2.73%
- Published 11.06.2018 21:29:12
- Last modified 21.11.2024 04:08:04
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.
CVE-2018-5095
- EPSS 3.09%
- Published 11.06.2018 21:29:12
- Last modified 21.11.2024 04:08:05
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerabilit...
CVE-2018-5096
- EPSS 1.65%
- Published 11.06.2018 21:29:12
- Last modified 21.11.2024 04:08:05
A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.
CVE-2018-5097
- EPSS 25.02%
- Published 11.06.2018 21:29:12
- Last modified 21.11.2024 04:08:05
A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash. This vulnerability affect...
CVE-2018-5098
- EPSS 3.09%
- Published 11.06.2018 21:29:12
- Last modified 21.11.2024 04:08:05
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefo...
CVE-2018-5099
- EPSS 3.13%
- Published 11.06.2018 21:29:12
- Last modified 21.11.2024 04:08:06
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used. This vulnerability affects...