CVE-2018-12371

CVSS v3.1 8.8 (High)
88% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.35 % (72th)
0.35% Progress
Affected Products 3
Advisories 12

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.

Weaknesses
CWE-190
Integer Overflow or Wraparound
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2020-07-09 14:15:10
(4 years ago)
Updated Date
2020-07-13 02:41:26
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 61.0 version cpe:2.3:a:mozilla:firefox < 61.0
  Mozilla Firefox Esr prior 60.1.0 version cpe:2.3:a:mozilla:firefox_esr < 60.1.0
  Mozilla Thunderbird prior 60.0 version cpe:2.3:a:mozilla:thunderbird < 60.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...