CVE-2018-18501 describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird, specifically versions prior to Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Rated as Critical (CVSS 9.8), this vulnerability is network-exploitable with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability through arbitrary code execution. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, its high FAUCET Risk Score and mention in media coverage suggest a notable level of concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 65.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 60.5CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 60.5CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.