A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this vulnerability does not affect WebExtensions. This vulnerability affects Firefox < 59.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade thunderbirdUpgrade waterfoxUpgrade firefoxUpgrade firefox-esrUpgrade linux-seamonkeyUpgrade linux-firefoxUpgrade seamonkeyUpgrade linux-thunderbirdUpgrade libxul | Dec 10, 2025 | Mar 13, 2018 |
| Mfsa2018 06 | — | Upgrade to Mozilla Firefox version 59.0 | Jul 12, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade mozillafirefoxUpgrade mozillafirefox-translations-commonUpgrade mozillafirefox-translations-other | May 20, 2018 | Mar 14, 2018 |
| Ubuntu | — | Upgrade firefox | Apr 26, 2018 | Mar 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub