Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5116

Опубликовано: 11 июн. 2018
Источник: debian
EPSS Низкий

Описание

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed58.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-02/#CVE-2018-5116

EPSS

Процентиль: 65%
0.00487
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

CVSS3: 9.8
nvd
больше 7 лет назад

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

CVSS3: 9.8
github
больше 3 лет назад

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость расширения WebExtensions браузера Mozilla Firefox, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 65%
0.00487
Низкий