Medium severity4.3NVD Advisory· Published Oct 18, 2018· Updated Jun 17, 2026
CVE-2018-12367
CVE-2018-12367
Description
In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18unspecified+ 2 more
- (no CPE)range: unspecified
- (no CPE)range: <60
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <60.0
unspecified+ 3 more
- (no CPE)range: unspecified
- (no CPE)range: unspecified
- (no CPE)range: <60.1
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <60.1.0
- osv-coords5 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweed
< 92.0-1.2+ 4 more
- (no CPE)range: < 92.0-1.2
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 60.2.1-3.13.1
- (no CPE)range: < 60.3.0-74.2
- (no CPE)range: < 91.1.1-1.1
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
Patches
Vulnerability mechanics
References
11- www.securityfocus.com/bid/104561nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1041193nvdThird Party AdvisoryVDB Entry
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions RequiredVendor Advisory
- lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201810-01nvdThird Party Advisory
- security.gentoo.org/glsa/201811-13nvdThird Party Advisory
- usn.ubuntu.com/3705-1/nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4295nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2018-15/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2018-16/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2018-19/nvdVendor Advisory
News mentions
0No linked articles in our index yet.