cbcvebase.
CVE-2018-12371
published 2020-07-09

CVE-2018-12371: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the…

PriorityP337high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.45%
70.1th percentile
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 61.0-1 (sid)firefox 61.0-1 (sid)
debianthunderbird< firefox 61.0-1 (sid)firefox 61.0-1 (sid)
mozillafirefox< 60.1.060.1.0
mozillafirefox< 61.061.0
mozillafirefox>= 0 < 61.0.1+build1-0ubuntu0.14.04.161.0.1+build1-0ubuntu0.14.04.1
mozillafirefox>= 0 < 61.0+build3-0ubuntu0.14.04.261.0+build3-0ubuntu0.14.04.2
mozillafirefox>= 0 < 61.0.1+build1-0ubuntu0.16.04.161.0.1+build1-0ubuntu0.16.04.1
mozillafirefox>= 0 < 61.0+build3-0ubuntu0.16.04.261.0+build3-0ubuntu0.16.04.2
mozillafirefox>= 0 < 61.0.1+build1-0ubuntu0.18.04.161.0.1+build1-0ubuntu0.18.04.1
mozillafirefox>= 0 < 61.0+build3-0ubuntu0.18.04.161.0+build3-0ubuntu0.18.04.1
mozillafirefox>= unspecified < 6161
mozillafirefox_esr>= unspecified < 60.160.1
mozillathunderbird< 60.060.0
mozillathunderbird>= 0 < 1:60.0-11:60.0-1
mozillathunderbird>= 0 < 1:60.0-11:60.0-1
mozillathunderbird>= 0 < 1:60.0-11:60.0-1
mozillathunderbird>= 0 < 1:60.0-11:60.0-1
mozillathunderbird>= unspecified < 6060

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.