---
title: "CVE-2018-18495\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2018-18495?format=md
keywords: index, follow
---

# CVE-2018-18495

Publication date 11 December 2018

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2018-18495?format=md#impact-score)

Toggle side navigation

## Description

WebExtension content scripts can be loaded into about: pages in some
circumstances, in violation of the permissions granted to extensions. This
could allow an extension to interfere with the loading and usage of these
pages and use capabilities that were intended to be restricted from
extensions. This vulnerability affects Firefox < 64.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 18.10 cosmic | Fixed 64.0+build3-0ubuntu0.18.10.1 |
| 18.04 LTS bionic | Fixed 64.0+build3-0ubuntu0.18.04.1 |
| 16.04 LTS xenial | Fixed 64.0+build3-0ubuntu0.16.04.1 |
| 14.04 LTS trusty | Fixed 64.0+build3-0ubuntu0.14.04.1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18495)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-18495)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2018-18495)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2018-18495)

### Related Ubuntu Security Notices (USN)

+ [USN-3844-1](https://usn.ubuntu.com/USN-3844-1)
+ Firefox vulnerabilities
+ 11 December 2018

### Other references

* <https://www.mozilla.org/en-US/security/advisories/mfsa2018-29/#CVE-2018-18495>
* <https://www.cve.org/CVERecord?id=CVE-2018-18495>
