CVE-2018-5170
- EPSS 0.88%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and ...
CVE-2018-5172
- EPSS 0.69%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:15
The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste mali...
CVE-2018-5173
- EPSS 1.03%
- Veröffentlicht 11.06.2018 21:29:15
- Zuletzt bearbeitet 21.11.2024 04:08:16
The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: th...
CVE-2018-5129
- EPSS 2.33%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 25.11.2025 17:50:16
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunde...
CVE-2018-5130
- EPSS 1.16%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 25.11.2025 17:50:16
When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
CVE-2018-5131
- EPSS 1.28%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 25.11.2025 17:50:16
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored...
CVE-2018-5132
- EPSS 0.91%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:10
The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability a...
CVE-2018-5133
- EPSS 0.64%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:10
If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences/in-content/preferences.xul" d...
CVE-2018-5136
- EPSS 0.86%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:11
A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vulnerability affects Firefox < 59.
CVE-2018-5137
- EPSS 1.36%
- Veröffentlicht 11.06.2018 21:29:14
- Zuletzt bearbeitet 21.11.2024 04:08:11
A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this vulnerability does not affect...