cbcvebase.
CVE-2018-12381
published 2018-10-18

CVE-2018-12381: Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly…

PriorityP425medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.84%
76.8th percentile
Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Firefox < 62.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianfirefox
debianfirefox-esr
mozillafirefox< 60.2.060.2.0
mozillafirefox< 62.062.0
mozillafirefox>= unspecified < 6262
mozillafirefox_esr>= unspecified < 60.260.2

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.