ZeroHour

CVE-2018-18498

CVSS 3.0
9.8 critical
EPSS
4%p90
Published
()
Modified
Description

A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

Vendors
mozilladebiancanonicalredhat
Products
firefox, firefox esr, thunderbird, debian linux, ubuntu linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation
Weakness
CWE-190, CWE-787
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.