peter bassill · operator
$ cve CVE-2018-12387 JSON

CVE-2018-12387

9.1
CRITICAL · CVSS 3.0 · EPSS 9.6% (pctl 95)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.

Scoring

CVSS9.1 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS9.59% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2018-10-18
Last modified2026-06-17

Affected (9)

VendorProduct
canonicalubuntu linux
debiandebian linux
mozillafirefox
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD