Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2018-5108 Information Exposure vulnerability in multiple products
A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab.
network
low complexity
mozilla canonical CWE-200
4.3
2018-06-11 CVE-2018-5106 Information Exposure vulnerability in multiple products
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when these tools are open.
network
low complexity
mozilla canonical CWE-200
5.3
2018-06-11 CVE-2017-7847 Information Exposure vulnerability in multiple products
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name.
network
low complexity
debian redhat mozilla CWE-200
4.3
2018-06-11 CVE-2017-7844 Information Exposure vulnerability in Mozilla Firefox
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history.
network
low complexity
mozilla CWE-200
6.5
2018-06-11 CVE-2017-7843 Information Exposure vulnerability in multiple products
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely.
network
low complexity
debian mozilla redhat CWE-200
7.5
2018-06-11 CVE-2017-7842 Information Exposure vulnerability in Mozilla Firefox
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one.
network
low complexity
mozilla CWE-200
5.3
2018-06-11 CVE-2017-7831 Information Exposure vulnerability in Mozilla Firefox
A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy objects.
network
low complexity
mozilla CWE-200
5.3
2018-06-11 CVE-2017-7812 Information Exposure vulnerability in Mozilla Firefox
If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to open.
network
low complexity
mozilla CWE-200
5.3
2018-06-11 CVE-2017-7787 Information Exposure vulnerability in multiple products
Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure.
network
low complexity
debian redhat mozilla CWE-200
7.5
2018-06-11 CVE-2017-7768 Information Exposure vulnerability in Mozilla Firefox
The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater.
local
low complexity
mozilla CWE-200
5.5