CVE-2018-5158 describes a critical vulnerability in the PDF viewer component of Firefox ESR versions prior to 52.8 and Firefox versions prior to 60. It allows for arbitrary JavaScript injection and execution with PDF viewer permissions through specially crafted PDF files, due to insufficient sanitization of PostScript calculator functions. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk with potential for high impact on confidentiality, integrity, and availability, requiring user interaction (opening a malicious PDF) for exploitation. While not listed in CISA's KEV catalog, its high FAUCET Risk Score of 97/100 and mentions in community discussions and media coverage suggest significant attention, though no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.