CVE-2018-5165
Last modified
CVE-2018-5165 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe Flash sandbox is actually enabled. The displayed state is the reverse of the true setting, resulting in user confusion. EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe Flash sandbox is actually enabled. The displayed state is the reverse of the true setting, resulting in user confusion. This could cause users to select this setting intending to activate it and inadvertently turn protections off. This vulnerability affects Firefox < 60.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 60.0 |
References
- http://www.securityfocus.com/bid/104139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040896Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1451452Exploit, Issue Tracking, Patch, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-11/Vendor Advisory
- http://www.securityfocus.com/bid/104139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040896Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1451452Exploit, Issue Tracking, Patch, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-11/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5165?
How severe is CVE-2018-5165?
How do I fix CVE-2018-5165?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5159An integer overflow can occur in the Skia library due to 32-…
- CVE-2018-5160WebRTC can use a "WrappedI420Buffer" pixel buffer but the ow…
- CVE-2018-5161Crafted message headers can cause a Thunderbird process to h…
- CVE-2018-5162Plaintext of decrypted emails can leak through the src attri…
- CVE-2018-5163If a malicious attacker has used another vulnerability to ga…
- CVE-2018-5164Content Security Policy (CSP) is not applied correctly to al…
- CVE-2018-5166WebExtensions can use request redirection and a "filterRepon…
- CVE-2018-5167The web console and JavaScript debugger do not sanitize all …
- CVE-2018-5168Sites can bypass security checks on permissions to install l…
- CVE-2018-5169If manipulated hyperlinked text with "chrome:" URL contained…
- CVE-2018-5170It is possible to spoof the filename of an attachment and di…
- CVE-2018-5172The Live Bookmarks page and the PDF viewer can run injected …
Are you affected by CVE-2018-5165?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
