CVE-2018-5159
- EPSS 37.56%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 25.11.2025 17:50:16
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This v...
CVE-2018-5160
- EPSS 2.37%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affe...
CVE-2018-5161
- EPSS 0.93%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5162
- EPSS 0.92%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
CVE-2018-5163
- EPSS 1.98%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the par...
CVE-2018-5164
- EPSS 0.37%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:14
Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and ot...
CVE-2018-5166
- EPSS 0.75%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects F...
CVE-2018-5167
- EPSS 0.65%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Add...
CVE-2018-5168
- EPSS 1.03%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 25.11.2025 17:50:16
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or ...
CVE-2018-5169
- EPSS 0.59%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the home page tabs. This vulnerability affects Firefox < 6...