#VU14905 Input validation error in Mozilla Firefox - CVE-2018-12385
Published: September 24, 2018
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists within the TransportSecurityInfo function due to insufficient validation of data stored in the local cache in the user profile directory. A remote attacker with ability to write data into local cache (e.g. with combination of another vulnerability) can execute arbitrary code on the target system.