Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12392

Опубликовано: 28 фев. 2019
Источник: debian
EPSS Низкий

Описание

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefox-esrfixed60.3.0esr-1package
firefoxfixed63.0-1package
thunderbirdfixed1:60.3.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12392

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/#CVE-2018-12392

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-28/#CVE-2018-12392

EPSS

Процентиль: 88%
0.03924
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 9.8
redhat
почти 7 лет назад

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 9.8
nvd
больше 6 лет назад

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 9.8
github
около 3 лет назад

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость браузеров Firefox и Firefox ESR и почтового клиента Thunderbird, связанная с ситуацией гонки в обработчике сигнала, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 88%
0.03924
Низкий