Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-5095

Опубликовано: 23 янв. 2018
Источник: redhat
CVSS3: 9.8

Описание

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

Дополнительная информация

Статус:

Important
Дефект:
CWE-190->CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1537817Mozilla: Integer overflow in Skia library during edge builder allocation (MFSA 2018-03)

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

CVSS3: 9.8
nvd
около 7 лет назад

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

CVSS3: 9.8
debian
около 7 лет назад

An integer overflow vulnerability in the Skia library when allocating ...

CVSS3: 9.8
github
около 3 лет назад

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

CVSS3: 9.8
fstec
больше 7 лет назад

Уязвимость библиотеки Skia браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

9.8 Critical

CVSS3