Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-12397
Description:A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-12397
BugTraq ID: 105718
http://www.securityfocus.com/bid/105718
Debian Security Information: DSA-4324 (Google Search)
https://www.debian.org/security/2018/dsa-4324
https://security.gentoo.org/glsa/201811-04
https://lists.debian.org/debian-lts-announce/2018/11/msg00008.html
RedHat Security Advisories: RHSA-2018:3005
https://access.redhat.com/errata/RHSA-2018:3005
RedHat Security Advisories: RHSA-2018:3006
https://access.redhat.com/errata/RHSA-2018:3006
http://www.securitytracker.com/id/1041944
https://usn.ubuntu.com/3801-1/




© 1998-2025 E-Soft Inc. All rights reserved.