CVE-2018-18504

Description

A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This results is a potentially exploitable crash and the possibility of reading from the memory of the freed buffers. This vulnerability affects Firefox < 65.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.737

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Mozilla Firefox 64.0.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 64.0.2Mac
Mozilla Open Source web browser (USN-3477-3) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3596-2) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3596-2) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3645-1) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3645-1) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3645-1) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3645-1) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3645-2) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3645-2) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3645-2) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3645-2) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3682-1) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3682-1) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3682-1) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3682-1) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3705-1) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3705-1) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3705-1) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3705-1) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3705-2) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3705-2) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3705-2) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3705-2) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3761-1) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3761-1) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3761-1) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3761-1) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3761-2) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3761-2) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3761-2) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3761-2) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3761-2) firefox_65.0+build2-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3761-2) firefox_65.0+build2-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3761-3) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3761-3) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3761-3) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3761-3) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3761-3) firefox_65.0+build2-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3761-3) firefox_65.0+build2-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3778-1) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3778-1) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3778-1) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3778-1) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3778-1) firefox_65.0+build2-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3778-1) firefox_65.0+build2-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3801-1) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3801-1) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3801-1) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3801-1) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3801-1) firefox_65.0+build2-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3801-1) firefox_65.0+build2-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3801-2) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3801-2) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3801-2) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3801-2) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3801-2) firefox_65.0+build2-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3801-2) firefox_65.0+build2-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3801-2) firefox_65.0+build2-0ubuntu0.18.10.1_amd64.debLinux
Mozilla Open Source web browser (USN-3801-2) firefox_65.0+build2-0ubuntu0.18.10.1_i386.debLinux
Mozilla Open Source web browser (USN-3844-1) firefox_65.0+build2-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3844-1) firefox_65.0+build2-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3844-1) firefox_65.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3844-1) firefox_65.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3844-1) firefox_65.0+build2-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source web browser (USN-3844-1) firefox_65.0+build2-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-3844-1) firefox_65.0+build2-0ubuntu0.18.10.1_i386.debLinux
Mozilla Open Source web browser (USN-3844-1) firefox_65.0+build2-0ubuntu0.18.10.1_amd64.debLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343015Mozilla Firefox (132.0.2)
PATCH-611870Mozilla Firefox For Mac (142.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234