Search CVE reports


Toggle filters

1421 – 1430 of 3038 results


CVE-2018-5152

Medium priority
Fixed

WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for...

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
Show less packages

CVE-2018-5151

Medium priority

Some fixes available 18 of 27

Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects...

3 affected packages

firefox, mozjs38, mozjs52

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
Show less packages

CVE-2018-5168

Medium priority
Fixed

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
thunderbird Fixed
Show less packages

CVE-2018-5159

Medium priority
Fixed

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
thunderbird Fixed
Show less packages

CVE-2018-5158

Medium priority
Fixed

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its...

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
Show less packages

CVE-2018-5157

Medium priority
Fixed

Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a...

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
Show less packages

CVE-2018-5155

Medium priority
Fixed

A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
thunderbird Fixed
Show less packages

CVE-2018-5154

Medium priority
Fixed

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8,...

2 affected packages

thunderbird, firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird Fixed
firefox Fixed
Show less packages

CVE-2018-5150

Medium priority

Some fixes available 34 of 41

Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run...

4 affected packages

mozjs38, firefox, mozjs52, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 Not in release Not in release Not in release Ignored
firefox Fixed Fixed Fixed Fixed
mozjs52 Not in release Not in release Ignored Fixed
thunderbird Fixed Fixed Fixed Fixed
Show less packages

CVE-2018-5148

Medium priority
Fixed

A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability...

2 affected packages

firefox, firefox-esr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
firefox-esr Not in release
Show less packages