CVE-2018-5144 — Integer Overflow or Wraparound in Mozilla Firefox ESR
Severity
7.3HIGHNVD
OSV8.8
EPSS
5.7%
top 9.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4
Affected Packages9 packages
Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, Enterprise Linux 7.4, 7.2, 7.5
🔴Vulnerability Details
4GHSA▶
GHSA-4xfj-vf8f-vwpp: An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter↗2022-05-14
CVEList▶
CVE-2018-5144: An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter↗2018-06-11
OSV▶
CVE-2018-5144: An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter↗2018-06-11
📋Vendor Advisories
3💬Community
1Bugzilla
▶