Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-18496

Опубликовано: 28 фев. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.8

Описание

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. Note: This issue only affects Windows operating systems. Other operating systems are not affected.. This vulnerability affects Firefox < 64.

РелизСтатусПримечание
bionic

not-affected

Windows only
cosmic

not-affected

Windows only
devel

not-affected

Windows only
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [Windows only]]
precise/esm

DNE

trusty

not-affected

Windows only
trusty/esm

DNE

trusty was not-affected [Windows only]
upstream

released

64.0
xenial

not-affected

Windows only

Показывать по

EPSS

Процентиль: 61%
0.00417
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
почти 7 лет назад

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.

CVSS3: 8.8
debian
почти 7 лет назад

When the RSS Feed preview about:feeds page is framed within another pa ...

CVSS3: 8.8
github
больше 3 лет назад

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.

CVSS3: 8.8
fstec
почти 7 лет назад

Уязвимость браузера Firefox, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 61%
0.00417
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3