The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.
The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue was discovered where the page could attempt to create these images through "file:" URLs from the local file system. This loading is blocked by the sandbox but could expose local data if combined with another attack that escapes sandbox protections. This vulnerability affects Firefox < 58.
Base Score: 5
Impact Score: 2.9
Exploitability Score: 10
Base Score: 5.3
Impact Score: 1.4
Exploitability Score: 3.9
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* versions up to 57.0.4 (inclusive)
|700326||Mozilla Firefox < 58 Multiple Vulnerabilities||Nessus Network Monitor||Web Clients|
|106790||Ubuntu 14.04 LTS / 16.04 LTS / 17.10 : firefox regressions (USN-3544-2)||Nessus||Ubuntu Local Security Checks|
|106347||Ubuntu 14.04 LTS / 16.04 LTS / 17.10 : firefox vulnerabilities (USN-3544-1)||Nessus||Ubuntu Local Security Checks|
|106303||Mozilla Firefox < 58 Multiple Vulnerabilities||Nessus||Windows|
|106301||Mozilla Firefox < 58 Multiple Vulnerabilities (macOS)||Nessus||MacOS X Local Security Checks|
|106288||FreeBSD : mozilla -- multiple vulnerabilities (a891c5b4-3d7a-4de9-9c71-eef3fd698c77)||Nessus||FreeBSD Local Security Checks|