4.3
CVSSv2

CVE-2018-5167

Published: 11/06/2018 Updated: 03/08/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Additionally, the JavaScript debugger will display "javascript:" links, which users could be tricked into clicking by malicious sites. This vulnerability affects Firefox < 60.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

canonical ubuntu linux 17.10

canonical ubuntu linux 14.04

mozilla firefox

Vendor Advisories

USN-3645-1 caused a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
The web console and JavaScript debugger do not sanitize all output that can be hyperlinked Both will display "chrome:" links as active, clickable hyperlinks in their output Web sites should not be able to directly link to internal chrome pages Additionally, the JavaScript debugger will display "javascript:" links, which users could be tricked in ...
Mozilla Foundation Security Advisory 2018-11 Security vulnerabilities fixed in Firefox 60 Announced May 9, 2018 Impact critical Products Firefox Fixed in Firefox 60 ...
The web console and JavaScript debugger in Firefox &lt; 600 do not sanitize all output that can be hyperlinked Both will display chrome: links as active, clickable hyperlinks in their output Web sites should not be able to directly link to internal chrome pages Additionally, the JavaScript debugger will display javascript: links, which users c ...