CVE-2018-5105: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent. This vulnerability affects Firefox < 58.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only
- Mozilla Firefox: up to and including 57.0.4
Published 2018-06-11. Last modified 2026-06-17.