CVE-2018-5165 describes a user interface vulnerability in 32-bit versions of Firefox prior to version 60, where the "Enable Adobe Flash protected mode" setting displayed the opposite of its true state, leading to user confusion. This medium-severity vulnerability (CVSS 5.3) could cause users to inadvertently disable Flash protections when attempting to enable them, potentially reducing security. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 60.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:x86:* | ||
< 60CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.