CVE-2018-18500

CRITICAL

Firefox < 65.0 - Use-After-Free in HTML5 Stream Parser

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-18500. PoCs published by sophoslabs.

AI-analyzed exploit summary This PoC demonstrates a use-after-free vulnerability in Firefox (CVE-2018-18500) via a custom HTTP server that serves a malicious HTML file and a delayed XML response to trigger the exploit. The server is designed to facilitate the exploitation process by simulating the necessary conditions.

Description

A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

Exploits (1)

nomisec WORKING POC 61 stars
by sophoslabs · poc
https://github.com/sophoslabs/CVE-2018-18500

This PoC demonstrates a use-after-free vulnerability in Firefox (CVE-2018-18500) via a custom HTTP server that serves a malicious HTML file and a delayed XML response to trigger the exploit. The server is designed to facilitate the exploitation process by simulating the necessary conditions.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Firefox (specific version not specified in code)
No auth needed
Prerequisites: Victim must visit the malicious server · Firefox browser with the vulnerable version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (17)

Core 17
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0219
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2019-01/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3897-1/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106781
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201903-04
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3874-1/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0269
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0218
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2019-02/
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4376
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/02/msg00024.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/01/msg00025.html
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2019-03/
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4392
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0270
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201904-07

Scores

CVSS v3 9.8
EPSS 0.1266
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (18)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
debian/debian_linux 8.0
debian/debian_linux 9.0
mozilla/firefox < 65.0
mozilla/firefox_esr < 60.5
mozilla/thunderbird < 60.5
redhat/enterprise_linux_desktop 6.0
... and 8 more
Published Feb 05, 2019
Tracked Since Feb 18, 2026