CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
87.0%
Multiple serious vulnerabilitieswere found in Mozilla Firefox and Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to bypass security restrictions, execute arbitrary code, gain privileges, perform cross-site scripting attack, spoof user interface, cause denial of service.
Below is a complete list of vulnerabilities:
Technical details
Vulnerabilities (2), (6)-(15) affects only Mozilla Firefox. Vulnerabilities (17, 18, 20) affects only Mozilla Firefox ESR. NB: This vulnerability does not have any public CVSS rating, so rating can be changed by the time.
Mozilla Foundation Security Advisory 2018-06
Mozilla Foundation Security Advisory 2018-07
CVE-2018-5127 high
CVE-2018-5129 warning
CVE-2018-5144 critical
CVE-2018-5125 high
CVE-2018-5145 critical
CVE-2018-5136 warning
CVE-2018-5126 critical
CVE-2018-5134 warning
CVE-2018-5137 warning
CVE-2018-5132 warning
CVE-2018-5133 warning
CVE-2018-5142 warning
CVE-2018-5138 warning
CVE-2018-5143 warning
CVE-2018-5130 high
CVE-2018-5128 critical
CVE-2018-5131 warning
CVE-2018-5140 warning
CVE-2018-5141 high
CVE-2018-5135 warning
Update to the latest versionDownload Mozilla Firefox
Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.
Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.
Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.
Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.
Cross site scripting. Exploitation of vulnerabilities with this impact can lead to partial interception of information transmitted between user and site.
Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
87.0%