Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-12377

Опубликовано: 18 окт. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

РелизСтатусПримечание
bionic

released

62.0+build2-0ubuntu0.18.04.3
devel

released

62.0+build2-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [62.0+build2-0ubuntu0.14.04.3]]
precise/esm

DNE

trusty

released

62.0+build2-0ubuntu0.14.04.3
trusty/esm

DNE

trusty was released [62.0+build2-0ubuntu0.14.04.3]
upstream

needs-triage

xenial

released

62.0+build2-0ubuntu0.16.04.3

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

60.2.0esr-1
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

released

1:60.2.1+build1-0ubuntu0.18.04.2
devel

released

1:60.2.1+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:60.2.1+build1-0ubuntu0.14.04.2]]
precise/esm

DNE

trusty

released

1:60.2.1+build1-0ubuntu0.14.04.2
trusty/esm

DNE

trusty was released [1:60.2.1+build1-0ubuntu0.14.04.2]
upstream

released

60.2.1
xenial

released

1:60.2.1+build1-0ubuntu0.16.04.4

Показывать по

EPSS

Процентиль: 83%
0.02021
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
почти 7 лет назад

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 9.8
nvd
почти 7 лет назад

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 9.8
debian
почти 7 лет назад

A use-after-free vulnerability can occur when refresh driver timers ar ...

CVSS3: 9.8
github
около 3 лет назад

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость веб-браузеров Firefox и Firefox ESR и почтового клиента Thunderbird, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код или вызвать аварийное завершение работы приложения

EPSS

Процентиль: 83%
0.02021
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3