6.5
CVSSv3

CVE-2018-18499

Published: 28/02/2019 Updated: 01/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

mozilla firefox esr

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2018-21 Security vulnerabilities fixed in Firefox ESR 602 Announced September 5, 2018 Impact critical Products Firefox ESR Fixed in Firefox ESR 602 ...
Mozilla Foundation Security Advisory 2018-20 Security vulnerabilities fixed in Firefox 62 Announced September 5, 2018 Impact critical Products Firefox Fixed in Firefox 62 ...
Mozilla Foundation Security Advisory 2018-25 Security vulnerabilities fixed in Thunderbird 6021 Announced October 4, 2018 Impact critical Products Thunderbird Fixed in Thunderbird 6021 ...