cbcvebase.
CVE-2017-5386
published 2018-06-11

CVE-2017-5386: WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or…

high7.3CVSS 3.0
AVNACLPRNUINSUCLILAL
WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianfirefox< firefox 51.0-1 (sid)firefox 51.0-1 (sid)
debianfirefox-esr< firefox 51.0-1 (sid)firefox 51.0-1 (sid)
mozillafirefox< 51.051.0
mozillafirefox< 45.7.045.7.0
mozillafirefox>= 0 < 51.0.1+build2-0ubuntu0.14.04.151.0.1+build2-0ubuntu0.14.04.1
mozillafirefox>= 0 < 51.0.1+build2-0ubuntu0.14.04.251.0.1+build2-0ubuntu0.14.04.2
mozillafirefox>= 0 < 51.0.1+build2-0ubuntu0.16.04.151.0.1+build2-0ubuntu0.16.04.1
mozillafirefox>= 0 < 51.0.1+build2-0ubuntu0.16.04.251.0.1+build2-0ubuntu0.16.04.2
mozillafirefox>= unspecified < 5151
mozillafirefox_esr>= unspecified < 45.745.7
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus

CVSS provenance

nvdv3.07.3HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv9.8CRITICAL