CVE Vulnerabilities

CVE-2018-5168

Published: Jun 11, 2018 | Modified: Nov 25, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
6.1 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Sites can bypass security checks on permissions to install lightweight themes by manipulating the baseURI property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

Affected Software

NameVendorStart VersionEnd Version
Debian_linuxDebian7.0 (including)7.0 (including)
Debian_linuxDebian8.0 (including)8.0 (including)
Debian_linuxDebian9.0 (including)9.0 (including)
Red Hat Enterprise Linux 6RedHatfirefox-0:52.8.0-1.el6_9*
Red Hat Enterprise Linux 6RedHatthunderbird-0:52.8.0-2.el6_9*
Red Hat Enterprise Linux 7RedHatfirefox-0:52.8.0-1.el7_5*
Red Hat Enterprise Linux 7RedHatthunderbird-0:52.8.0-1.el7_5*
FirefoxUbuntuartful*
FirefoxUbuntubionic*
FirefoxUbuntudevel*
FirefoxUbuntutrusty*
FirefoxUbuntuupstream*
FirefoxUbuntuxenial*
ThunderbirdUbuntuartful*
ThunderbirdUbuntubionic*
ThunderbirdUbuntudevel*
ThunderbirdUbuntutrusty*
ThunderbirdUbuntuupstream*
ThunderbirdUbuntuxenial*

References