CVE-2018-18495
Last modified
CVE-2018-18495 is a vulnerability of currently unknown severity. WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 64.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 18.10 |
References
- http://www.securityfocus.com/bid/106167Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1427585Issue Tracking, Permissions Required, Vendor Advisory
- https://usn.ubuntu.com/3844-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-29/Vendor Advisory
- http://www.securityfocus.com/bid/106167Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1427585Issue Tracking, Permissions Required, Vendor Advisory
- https://usn.ubuntu.com/3844-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-29/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18495?
How severe is CVE-2018-18495?
How do I fix CVE-2018-18495?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-18487In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, th…
- CVE-2018-18488In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQ…
- CVE-2018-18489The ping feature in the Diagnostic functionality on TP-LINK …
- CVE-2018-18492A use-after-free vulnerability can occur after deleting a se…
- CVE-2018-18493A buffer overflow can occur in the Skia library during buffe…
- CVE-2018-18494A same-origin policy violation allowing the theft of cross-o…
- CVE-2018-18496When the RSS Feed preview about:feeds page is framed within …
- CVE-2018-18497Limitations on the URIs allowed to WebExtensions by the brow…
- CVE-2018-18498A potential vulnerability leading to an integer overflow can…
- CVE-2018-18499A same-origin policy violation allowing the theft of cross-o…
- CVE-2018-1850IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9…8.8
- CVE-2018-18500A use-after-free vulnerability can occur while parsing an HT…
Are you affected by CVE-2018-18495?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
