AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-5133

MEDIUM · CVSS 6.5 EPSS 1.54%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-06-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-5133
Severity
MEDIUM
CVSS
6.5
EPSS
1.54%
Chrome Firefox

Original NVD Description

If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences/in-content/preferences.xul" directly in a tab and executes a search. This stored preference is also executed whenever an EME video player plugin displays a CDM-disabled message as a notification message. This vulnerability affects Firefox < 59.