CVE-2018-12396 PUBLISHED

A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

EPSS 1.14% · 78.3th percentile

Risk Scores

EPSS Score
1.14%
78.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSfirefox62.0.3+build1-0ubuntu0.18.04.1, 62.0+build2-0ubuntu0.18.04.5, 62.0+build2-0ubuntu0.18.04.4
Ubuntu:14.04:LTSfirefox35.0+build3-0ubuntu0.14.04.2, 35.0.1+build1-0ubuntu0.14.04.1, 36.0+build2-0ubuntu0.14.04.4
Ubuntu:16.04:LTSfirefox56.0+build6-0ubuntu0.16.04.2, 50.0+build2-0ubuntu0.16.04.2, 50.0.2+build1-0ubuntu0.16.04.1
Ubuntu:18.04:LTSmozjs380, 38.8.0~repack1-0ubuntu4, 38.8.0~repack1-0ubuntu3
Ubuntu:20.04:LTSmozjs5252.9.1-1ubuntu3, 0, 52.9.1-1build1
Ubuntu:18.04:LTSmozjs5252.3.1-7fakesync1, 52.3.1-0ubuntu3, 0

Timeline

References

Open in Interactive Console →