ZeroHour

CVE-2018-12378

CVSS 3.0
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

Vendors
redhatdebiancanonicalmozilla
Products
enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, debian linux, ubuntu linux, firefox, thunderbird
Weakness
CWE-416
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.