CVE-2018-5159
CRITICALSkia - Buffer Overflow
Title source: llmDescription
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Google Security Research · htmldosmultiple
https://www.exploit-db.com/exploits/44759
References (19)
Scores
CVSS v3
9.8
EPSS
0.3756
EPSS Percentile
97.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-190
CWE-787
Status
published
Products (20)
canonical/ubuntu_linux
14.04
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
17.10
canonical/ubuntu_linux
18.04
debian/debian_linux
7.0
debian/debian_linux
8.0
debian/debian_linux
9.0
mozilla/firefox
< 52.8.0
mozilla/thunderbird
< 52.8.0
mozilla/thunderbird_esr
< 52.8.0
... and 10 more
Published
Jun 11, 2018
Tracked Since
Feb 18, 2026