Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-18495

Опубликовано: 28 фев. 2019
Источник: debian
EPSS Низкий

Описание

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed64.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-29/#CVE-2018-18495

EPSS

Процентиль: 55%
0.00328
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
redhat
около 7 лет назад

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
nvd
почти 7 лет назад

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
github
больше 3 лет назад

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
fstec
почти 7 лет назад

Уязвимость компонента WebExtension браузера Firefox, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 55%
0.00328
Низкий