CVE-2018-5185
- EPSS 0.35%
- Veröffentlicht 11.06.2018 21:29:16
- Zuletzt bearbeitet 21.11.2024 04:08:17
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5154
- EPSS 3.07%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:13
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Fir...
CVE-2018-5155
- EPSS 3.07%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:13
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox E...
CVE-2018-5159
- EPSS 40.64%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This v...
CVE-2018-5161
- EPSS 0.93%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5162
- EPSS 0.97%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5168
- EPSS 1.03%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or ...
CVE-2018-5170
- EPSS 0.88%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and ...
CVE-2018-5174
- EPSS 0.54%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:16
In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not show any UI. Files that are unknown and potentially dangerous will be allowed to run because SmartSc...
CVE-2018-5129
- EPSS 2.44%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:10
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunde...