CVE-2018-5157
- EPSS 0.62%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:13
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website....
CVE-2018-5158
- EPSS 58.98%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnera...
CVE-2018-5159
- EPSS 40.64%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This v...
CVE-2018-5161
- EPSS 0.93%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5162
- EPSS 0.97%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5168
- EPSS 1.03%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or ...
CVE-2018-5170
- EPSS 0.88%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and ...
CVE-2018-5129
- EPSS 2.44%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:10
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunde...
CVE-2018-5130
- EPSS 1.22%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:10
When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
CVE-2018-5131
- EPSS 1.48%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:10
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored...