Mozilla has published security advisories to address multiple vulnerabilities found in Firefox. A remote attacker could entice a user running the vulnerable browser to open a web page with specially crafted content to exploit the vulnerabilities.
Successful exploitation of the vulnerabilities could lead to arbitrary code execution, information disclosure, restriction bypass, sandbox escape, cross-site scripting or application crash on an affected system.
Mozilla has released new versions of the product to address the issues and they can be downloaded at the following URLs:
Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/
https://www.hkcert.org/my_url/en/alert/18051001
https://www.us-cert.gov/ncas/current-activity/2018/05/09/Mozilla-Releases-Security-Updates-Firefox
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5150 (to CVE-2018-5155)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5157 (to CVE-2018-5160)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5163 (to CVE-2018-5169)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5172 (to CVE-2018-5178)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5180 (to CVE-2018-5183)