Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.
El contenido web podría acceder a información en la caché HTTP si e10s está deshabilitado. Esto podría revelar algunas URL visitadas y el contenido de dichas páginas. Este problema afecta a Firefox 48 y 49. La vulnerabilidad afecta a Firefox en versiones anteriores a la 49.0.2.
A use-after-free was discovered in service workers. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via program crash, or execute arbitrary code. It was discovered that web content could access information in the HTTP cache in some circumstances. An attacker could potentially exploit this to obtain sensitive information. Various other issues were also addressed.