cbcvebase.
CVE-2018-12393
published 2019-02-28

CVE-2018-12393: A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could…

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianfirefox< firefox 63.0-1 (sid)firefox 63.0-1 (sid)
debianfirefox-esr< firefox 63.0-1 (sid)firefox 63.0-1 (sid)
debianthunderbird< firefox 63.0-1 (sid)firefox 63.0-1 (sid)
mozillafirefox< 63.063.0
mozillafirefox>= 0 < 63.0.3+build1-0ubuntu0.14.04.163.0.3+build1-0ubuntu0.14.04.1
mozillafirefox>= 0 < 63.0+build2-0ubuntu0.14.04.263.0+build2-0ubuntu0.14.04.2
mozillafirefox>= 0 < 63.0.3+build1-0ubuntu0.16.04.163.0.3+build1-0ubuntu0.16.04.1
mozillafirefox>= 0 < 63.0+build2-0ubuntu0.16.04.263.0+build2-0ubuntu0.16.04.2
mozillafirefox>= 0 < 63.0.3+build1-0ubuntu0.18.04.163.0.3+build1-0ubuntu0.18.04.1
mozillafirefox>= 0 < 63.0+build2-0ubuntu0.18.04.263.0+build2-0ubuntu0.18.04.2
mozillafirefox>= unspecified < 6363
mozillafirefox_esr< 60.360.3
mozillafirefox_esr>= unspecified < 60.360.3
mozillathunderbird< 60.360.3
mozillathunderbird>= unspecified < 60.360.3
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH