High severity8.8NVD Advisory· Published Oct 18, 2018· Updated Jun 17, 2026
CVE-2018-12361
CVE-2018-12361
Description
An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <61.0
- cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*range: <60.1
- (no CPE)range: <60.1
- (no CPE)range: unspecified
- (no CPE)range: unspecified
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <60.0
- (no CPE)range: <60
- (no CPE)range: unspecified
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- osv-coords5 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012
< 92.0-1.2+ 4 more
- (no CPE)range: < 92.0-1.2
- (no CPE)range: < 91.1.1-1.1
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 60.2.1-3.13.1
- (no CPE)range: < 60.3.0-74.2
Patches
Vulnerability mechanics
References
11- www.securityfocus.com/bid/104558nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1041193nvdThird Party AdvisoryVDB Entry
- lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlnvdThird Party Advisory
- security.gentoo.org/glsa/201810-01nvdMitigationThird Party Advisory
- security.gentoo.org/glsa/201811-13nvdMitigationThird Party Advisory
- usn.ubuntu.com/3705-1/nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4295nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2018-15/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2018-16/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2018-19/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions Required
News mentions
0No linked articles in our index yet.