2024

2023

2022

2021

2020

2019

2018

CVE-2018-5172 (v3: 4.3) 11 Jun 2018
The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.

2017

2016

2015