The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.
Base Score: 6.8
Impact Score: 6.4
Exploitability Score: 8.6
Base Score: 8.8
Impact Score: 5.9
Exploitability Score: 2.8
|122192||Mozilla Firefox < 64.0||Nessus||MacOS X Local Security Checks|
|700411||Mozilla Firefox < 64 Multiple Vulnerabilities||Nessus Network Monitor||Web Clients|
|119636||FreeBSD : mozilla -- multiple vulnerabilities (d10b49b2-8d02-49e8-afde-0844626317af)||Nessus||FreeBSD Local Security Checks|
|119604||Mozilla Firefox < 64.0 Multiple Vulnerabilities||Nessus||Windows|
|119603||Mozilla Firefox < 64.0 Multiple Vulnerabilities (macOS) (deprecated)||Nessus||MacOS X Local Security Checks|