CVE-2018-18495

MEDIUM

Mozilla Firefox < 64.0 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2018-29/
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1427585
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3844-1/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106167

Scores

CVSS v3 6.5
EPSS 0.0033
EPSS Percentile 55.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-732
Status published
Products (5)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
mozilla/firefox < 64.0
Published Feb 28, 2019
Tracked Since Feb 18, 2026