← All CVEs

CVE-2018-12386

high · 8.1

A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.

8.1
CVSS
13.4%
EPSS (exploit prob.)
96th
EPSS percentile
2018-10-18
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Weaknesses

CWE-704

Affected products

VendorProductAffected versions
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_aus7.6
redhatenterprise_linux_server_eus7.5
redhatenterprise_linux_server_eus7.6
redhatenterprise_linux_server_tus7.6
redhatenterprise_linux_workstation6.0
redhatenterprise_linux_workstation7.0
debiandebian_linux9.0
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
mozillafirefox< 60.2.2
mozillafirefox< 62.0.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-12386