Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-18497
Description:Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-18497
BugTraq ID: 106167
http://www.securityfocus.com/bid/106167
https://usn.ubuntu.com/3844-1/




© 1998-2025 E-Soft Inc. All rights reserved.