Aller au contenu
appaloosa scout logo main rounded
MEDIUM 6.5

CVE-2018-18494

EN A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS 1.1% percentile 77.9%

Apps suivies affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
mozilla thunderbird Windows <60.4.0 cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Voir sur NVD ↗