CVE-2018-5127 describes a high-severity buffer overflow vulnerability affecting Mozilla Firefox (versions prior to 59), Firefox ESR (prior to 52.7), and Thunderbird (prior to 52.7). This flaw occurs when manipulating the SVG "animatedPathSegList" via script, leading to a potentially exploitable crash. The vulnerability has a CVSS score of 8.8 (High), indicating it can be exploited remotely with low complexity, requiring user interaction, and potentially leading to high impact on confidentiality, integrity, and availability. While the EPSS score suggests a low likelihood of exploitation compared to most CVEs, there is no public exploit code available, nor is it listed in the CISA KEV catalog, indicating it is not currently under active exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.4CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.