A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this vulnerability does not affect WebExtensions. This vulnerability affects Firefox < 59.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | freebsd-upgrade-package-firefoxfreebsd-upgrade-package-waterfoxfreebsd-upgrade-package-seamonkeyfreebsd-upgrade-package-linux-seamonkeyfreebsd-upgrade-package-firefox-esrfreebsd-upgrade-package-linux-firefoxfreebsd-upgrade-package-libxulfreebsd-upgrade-package-thunderbirdfreebsd-upgrade-package-linux-thunderbird | Dec 10, 2025 | Mar 13, 2018 | |
| Mfsa2018 06 | mozilla-firefox-upgrade-59_0 | Jul 12, 2018 | Jun 11, 2018 | |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-other | May 20, 2018 | Mar 14, 2018 |
| Ubuntu | ubuntu-upgrade-firefox | Apr 26, 2018 | Mar 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub