VulnerabilityModified
CVE-2018-18495
This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions.
MEDIUM 6.5EPSS 1.67%
Does this matter?
Lower severity and a low EPSS score (1.67%). Track it; it rarely justifies an emergency change on its own.
Description
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 1.67% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- mozilla/firefox · canonical/ubuntu linux
- Source
- security@mozilla.org
References
- http://www.securityfocus.com/bid/106167Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1427585Issue Tracking, Permissions Required, Vendor Advisory
- https://usn.ubuntu.com/3844-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-29/Vendor Advisory
- http://www.securityfocus.com/bid/106167Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1427585Issue Tracking, Permissions Required, Vendor Advisory
- https://usn.ubuntu.com/3844-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-29/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.