Back to search
CVE-2018-18496
Published: Feb 28, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 64 |
References
https://www.mozilla.org/security/advisories/mfsa2018-29/
x_refsource_CONFIRM
https://bugzilla.mozilla.org/show_bug.cgi?id=1422231
x_refsource_CONFIRM
106167
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now