CVE-2018-12386
published 2018-10-18CVE-2018-12386: A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution…
high8.1CVSS 3.0
AVNACLPRNUIRSUCHIHAN
A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 62.0.3-1 (sid) | firefox 62.0.3-1 (sid) |
| debian | firefox-esr | < firefox 62.0.3-1 (sid) | firefox 62.0.3-1 (sid) |
| mozilla | firefox | < 60.2.2 | 60.2.2 |
| mozilla | firefox | < 62.0.3 | 62.0.3 |
| mozilla | firefox | >= 0 < 62.0.3+build1-0ubuntu0.14.04.2 | 62.0.3+build1-0ubuntu0.14.04.2 |
| mozilla | firefox | >= 0 < 62.0.3+build1-0ubuntu0.16.04.2 | 62.0.3+build1-0ubuntu0.16.04.2 |
| mozilla | firefox | >= 0 < 62.0.3+build1-0ubuntu0.18.04.1 | 62.0.3+build1-0ubuntu0.18.04.1 |
| mozilla | firefox | >= unspecified < 62.0.3 | 62.0.3 |
| mozilla | firefox_esr | >= unspecified < 60.2.2 | 60.2.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
osv8.1HIGH