First published: Wed May 09 2018(Updated: )
Last updated 24 July 2024
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <60 | 60 |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Canonical Ubuntu Linux | =18.04 | |
Mozilla Firefox | <60.0 | |
debian/firefox | 131.0.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-5176 is a vulnerability in the JSON Viewer of Mozilla Firefox that allows for the execution of malicious JavaScript code through clickable hyperlinks.
CVE-2018-5176 works by displaying clickable hyperlinks for URLs in a JSON file, including 'javascript:' links, which can trick users into executing malicious code.
Mozilla Firefox versions up to and exclusive of 60.0, as well as Ubuntu with Firefox versions up to and exclusive of 60.0, are affected by CVE-2018-5176.
CVE-2018-5176 has a severity value of 6.1, indicating a medium severity level.
To fix CVE-2018-5176, update your Mozilla Firefox or Ubuntu with Firefox to a version higher than 60.0.