CVE-2018-5183
Description
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.916
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Updates for Mozilla Firefox ESR (52.8.0) | Windows |
| Updates for Mozilla Firefox ESR (x64) (52.8.0) | Windows |
| Mozilla Thunderbird (52.8.0) | Windows |
| Updates for Mozilla Firefox ESR (52.8.1) | Windows |
| Updates for Mozilla Firefox ESR (x64) (52.8.1) | Windows |
| Multiple Vulnerabilities are affected in Firefox ESR for Mac 52.7.4 | Mac |
| Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 52.7.4 | Mac |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird for Mac 45.8.0 | Mac |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird for Mac 52.7.0 | Mac |
| Multiple vulnerabilities are fixed in Mozilla Firefox For Mac 52.8 | Mac |
| (RHSA-2018:1414) Critical: firefox security update firefox-52.8.0-1.el6_9.i686.rpm | Linux |
| (RHSA-2018:1414) Critical: firefox security update firefox-52.8.0-1.el6_9.x86_64.rpm | Linux |
| (RHSA-2018:1415) Critical: firefox security update firefox-52.8.0-1.el7_5.i686.rpm | Linux |
| (RHSA-2018:1415) Critical: firefox security update firefox-52.8.0-1.el7_5.x86_64.rpm | Linux |
| (RHSA-2018:1725) Important: thunderbird security update thunderbird-52.8.0-1.el7_5.x86_64.rpm | Linux |
| (RHSA-2018:1726) Important: thunderbird security update thunderbird-52.8.0-2.el6_9.i686.rpm | Linux |
| (RHSA-2018:1726) Important: thunderbird security update thunderbird-52.8.0-2.el6_9.x86_64.rpm | Linux |
| SUSE-SU-2019:2872-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-68.2.0-109.95.2.x86_64.rpm | Linux |
| SUSE-SU-2019:2872-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-debuginfo-68.2.0-109.95.2.x86_64.rpm | Linux |
| SUSE-SU-2019:2872-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-debugsource-68.2.0-109.95.2.x86_64.rpm | Linux |
| SUSE-SU-2019:2872-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-translations-common-68.2.0-109.95.2.x86_64.rpm | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-307503 | Updates for Mozilla Firefox ESR (52.8.0) |
| PATCH-307508 | Updates for Mozilla Firefox ESR (x64) (52.8.0) |
| PATCH-307561 | Mozilla Thunderbird (52.8.0) |
| PATCH-307643 | Updates for Mozilla Firefox ESR (52.8.1) |
| PATCH-307647 | Updates for Mozilla Firefox ESR (x64) (52.8.1) |
| PATCH-611808 | Mozilla Firefox ESR for MAC 128.14.0 |
| PATCH-611870 | Mozilla Firefox For Mac (142.0.1) |
| PATCH-611807 | Mozilla Thunderbird For Mac (142.0) |
| PATCH-611807 | Mozilla Thunderbird For Mac (142.0) |
| PATCH-612783 | Mozilla Firefox For Mac (145.0.1) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234