Логотип exploitDog
bind:CVE-2018-18497
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-18497

Количество 6

Количество 6

ubuntu логотип

CVE-2018-18497

почти 7 лет назад

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-18497

около 7 лет назад

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-18497

почти 7 лет назад

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-18497

почти 7 лет назад

Limitations on the URIs allowed to WebExtensions by the browser.window ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9467-r3c9-7387

больше 3 лет назад

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2020-00610

почти 7 лет назад

Уязвимость компонента WebExtension браузера Firefox, связанная с некорректным ограничением URI, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-18497

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-18497

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

CVSS3: 6.5
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-18497

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-18497

Limitations on the URIs allowed to WebExtensions by the browser.window ...

CVSS3: 6.5
0%
Низкий
почти 7 лет назад
github логотип
GHSA-9467-r3c9-7387

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-00610

Уязвимость компонента WebExtension браузера Firefox, связанная с некорректным ограничением URI, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 6.5
0%
Низкий
почти 7 лет назад

Уязвимостей на страницу