Month | Quarter | Year |
---|---|---|
#16 | #16 | #16 |
CVE-ID | CWE-ID | Type | Score |
---|---|---|---|
CVE-2018-18494 | CWE-346 | Origin Validation Error | 6.5 |
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. |
|||
CVE-2018-18493 | CWE-119 | Buffer Errors | 9.8 |
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. |
|||
CVE-2018-18492 | CWE-416 | Use After Free | 9.8 |
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. |
|||
CVE-2018-12407 | CWE-119 | Buffer Errors | 9.8 |
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. |
|||
CVE-2018-12406 | CWE-119 | Buffer Errors | 8.8 |
Mozilla developers and community members Alex Gaynor, André Bargull, Boris Zbarsky, Christian Holler, Jan de Mooij, Jason Kratzer, Philipp, Ronald Crane, Natalia Csoregi, and Paul Theriault reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. |
|||
CVE-2018-12405 | CWE-119 | Buffer Errors | 9.8 |
Mozilla developers and community members Christian Holler, Diego Calleja, Andrew McCreight, Jon Coppeard, Jed Davis, Natalia Csoregi, Nicolas B. Pierron, and Tyson Smith reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. |
|||
CVE-2018-12403 | CWE-254 | Security Features | 5.3 |
If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. |
|||
CVE-2018-12402 | CWE-284 | Improper Access Control | 6.5 |
SameSite cookies are sent on cross-origin requests when the "Save Page As..." menu item is selected to save a page, violating cookie policy. This can result in saving the wrong version of resources based on those cookies. |
|||
CVE-2018-12401 | CWE-20 | Input Validation | 7.5 |
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. |
|||
CVE-2018-12400 | CWE-200 | Information Leak / Disclosure | 5.3 |
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions.
Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected. |