ZeroHour

CVE-2018-5154

CVSS 3.0
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

Vendors
debianredhatmozillacanonical
Products
debian linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, firefox, thunderbird, thunderbird esr, ubuntu linux
Weakness
CWE-416
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.