668
VMScore

CVE-2018-12369

Published: 18/10/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox esr

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 17.10

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
USN-3705-1 caused some minor regressions in Firefox ...
WebExtensions bundled with embedded experiments were not correctly checked for proper authorization This allowed a malicious WebExtension to gain full browser permissions This vulnerability affects Firefox ESR &lt; 601 and Firefox &lt; 61 ...
Mozilla Foundation Security Advisory 2018-16 Security vulnerabilities fixed in Firefox ESR 601 Announced June 26, 2018 Impact critical Products Firefox ESR Fixed in Firefox ESR 601 ...
Mozilla Foundation Security Advisory 2018-15 Security vulnerabilities fixed in Firefox 61 Announced June 26, 2018 Impact critical Products Firefox Fixed in Firefox 61 ...
WebExtensions bundled with embedded experiments were not correctly checked for proper authorization before Firefox 610 This allowed a malicious WebExtension to gain full browser permissions ...