Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12386

Опубликовано: 02 окт. 2018
Источник: redhat
CVSS3: 8.8
EPSS Средний

Описание

A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7thunderbirdNot affected
Red Hat Enterprise Linux 6firefoxFixedRHSA-2018:288108.10.2018
Red Hat Enterprise Linux 7firefoxFixedRHSA-2018:288408.10.2018

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-843->CWE-125
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1635451Mozilla: type confusion in JavaScript

EPSS

Процентиль: 97%
0.41656
Средний

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 7 лет назад

A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.

CVSS3: 8.1
nvd
почти 7 лет назад

A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.

CVSS3: 8.1
debian
почти 7 лет назад

A vulnerability in register allocation in JavaScript can lead to type ...

CVSS3: 8.1
github
около 3 лет назад

A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.

CVSS3: 8.1
fstec
почти 7 лет назад

Уязвимость веб-браузеров Firefox, Firefox ESR, связанная с ошибками преобразования типов данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.41656
Средний

8.8 High

CVSS3