CVE-2018-5105: High severity firefox vulnerability
Last updated 24 July 2024
Other sources
WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5091
- CVE-2018-5092
- CVE-2018-5093
- CVE-2018-5094
- CVE-2018-5095
- CVE-2018-5097
- CVE-2018-5098
- CVE-2018-5099
- CVE-2018-5100
- CVE-2018-5101
- CVE-2018-5102
- CVE-2018-5103
- CVE-2018-5104
- CVE-2018-5105
- CVE-2018-5106
- CVE-2018-5107
- CVE-2018-5108
- CVE-2018-5109
- CVE-2018-5110
- CVE-2018-5111
- CVE-2018-5112
- CVE-2018-5113
- CVE-2018-5114
- CVE-2018-5115
- CVE-2018-5116
- CVE-2018-5117
- CVE-2018-5118
- CVE-2018-5119
- CVE-2018-5121
- CVE-2018-5122
- CVE-2018-5090
- CVE-2018-5089
Frequently Asked Questions
What is CVE-2018-5105?
CVE-2018-5105 is a vulnerability in Firefox < 58 that allows WebExtensions to bypass user prompts and run an executable file with local user privileges without explicit user consent.
How does CVE-2018-5105 affect Firefox?
CVE-2018-5105 affects Firefox versions prior to 58.
What is the severity of CVE-2018-5105?
The severity of CVE-2018-5105 is high with a CVSS score of 7.
How can I fix CVE-2018-5105?
To fix CVE-2018-5105, make sure you are using Firefox version 58 or higher.
Where can I find more information about CVE-2018-5105?
You can find more information about CVE-2018-5105 on the Mozilla Bugzilla and Mozilla Security Advisories websites.