Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12392

Опубликовано: 23 окт. 2018
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 6firefoxFixedRHSA-2018:300624.10.2018
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2018:353109.11.2018
Red Hat Enterprise Linux 7firefoxFixedRHSA-2018:300524.10.2018
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2018:353209.11.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-364
https://bugzilla.redhat.com/show_bug.cgi?id=1642182Mozilla: Crash with nested event loops

EPSS

Процентиль: 90%
0.05334
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 9.8
nvd
больше 6 лет назад

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 9.8
debian
больше 6 лет назад

When manipulating user events in nested loops while opening a document ...

CVSS3: 9.8
github
около 3 лет назад

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость браузеров Firefox и Firefox ESR и почтового клиента Thunderbird, связанная с ситуацией гонки в обработчике сигнала, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 90%
0.05334
Низкий

9.8 Critical

CVSS3