Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12371

Опубликовано: 09 июл. 2020
Источник: debian
EPSS Низкий

Описание

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed61.0-1package
thunderbirdfixed1:60.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-15/#CVE-2018-12371

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-19/#CVE-2018-12371

EPSS

Процентиль: 71%
0.01446
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.

CVSS3: 8.8
redhat
около 8 лет назад

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.

CVSS3: 8.8
nvd
около 6 лет назад

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.

CVSS3: 8.8
github
около 4 лет назад

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.

CVSS3: 6.1
fstec
около 8 лет назад

Уязвимость библиотеки Skia браузеров Firefox и Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 71%
0.01446
Низкий