CVE-2018-5154
- EPSS 3.26%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Fir...
CVE-2018-5155
- EPSS 3.45%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox E...
CVE-2018-5159
- EPSS 21.04%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 25.11.2025 17:50:16
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This v...
CVE-2018-5161
- EPSS 2.05%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5162
- EPSS 1.95%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5168
- EPSS 2.38%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 25.11.2025 17:50:16
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or ...
CVE-2018-5170
- EPSS 1.76%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and ...
CVE-2018-5174
- EPSS 1.85%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 25.11.2025 17:50:16
In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not show any UI. Files that are unknown and potentially dangerous will be allowed to run because SmartSc...
CVE-2018-5129
- EPSS 3.01%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 25.11.2025 17:50:16
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunde...
CVE-2018-5144
- EPSS 3.26%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 25.11.2025 17:50:16
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.