5.3
CVSSv3

CVE-2018-12381

Published: 18/10/2018 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Firefox < 62.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox_esr

mozilla firefox

Vendor Advisories

Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL *Note: this issue only affects Windows operating systems with Outlook installed Other operating systems are not affected* This vulnerability affects Firefox ESR &lt; 602 an ...
Mozilla Foundation Security Advisory 2018-21 Security vulnerabilities fixed in Firefox ESR 602 Announced September 5, 2018 Impact critical Products Firefox ESR Fixed in Firefox ESR 602 ...
Mozilla Foundation Security Advisory 2018-20 Security vulnerabilities fixed in Firefox 62 Announced September 5, 2018 Impact critical Products Firefox Fixed in Firefox 62 ...