VulnerabilityModified
CVE-2018-5165
This vulnerability affects Firefox < 60.
MEDIUM 5.3EPSS 1.67%
Does this matter?
Lower severity and a low EPSS score (1.67%). Track it; it rarely justifies an emergency change on its own.
Description
In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe Flash sandbox is actually enabled. The displayed state is the reverse of the true setting, resulting in user confusion. This could cause users to select this setting intending to activate it and inadvertently turn protections off. This vulnerability affects Firefox < 60.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.67% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox
- Source
- security@mozilla.org
References
- http://www.securityfocus.com/bid/104139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040896Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1451452Exploit, Issue Tracking, Patch, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-11/Vendor Advisory
- http://www.securityfocus.com/bid/104139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040896Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1451452Exploit, Issue Tracking, Patch, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-11/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.