CVE-2018-12371

8.8 HIGH
Published: July 09, 2020 Modified: November 25, 2025

Description

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1465686
Source: security@mozilla.org
Exploit Issue Tracking Patch Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-15/
Source: security@mozilla.org
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-16/
Source: security@mozilla.org
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-19/
Source: security@mozilla.org
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1465686
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Issue Tracking Patch Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-15/
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-16/
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-19/
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
8.8 / 10.0
EPSS (Exploit Probability)
0.5%
65th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

mozilla