CVE-2018-5166
- EPSS 0.79%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects F...
CVE-2018-5167
- EPSS 0.65%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Add...
CVE-2018-5168
- EPSS 1.03%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or ...
CVE-2018-5169
- EPSS 0.59%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the home page tabs. This vulnerability affects Firefox < 6...
CVE-2018-5172
- EPSS 0.69%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste mali...
CVE-2018-5173
- EPSS 1.03%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:16
The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: th...
CVE-2018-5174
- EPSS 0.54%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:16
In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not show any UI. Files that are unknown and potentially dangerous will be allowed to run because SmartSc...
CVE-2018-5129
- EPSS 2.44%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:10
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunde...
CVE-2018-5130
- EPSS 1.22%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:10
When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
CVE-2018-5131
- EPSS 1.48%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:10
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored...