Critical severity9.8NVD Advisory· Published Feb 5, 2019· Updated Jun 17, 2026
CVE-2018-18501
CVE-2018-18501
Description
Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
77unspecified+ 2 more
- (no CPE)range: unspecified
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <60.5
- (no CPE)range: <60.5
unspecified+ 4 more
- (no CPE)range: unspecified
- (no CPE)range: unspecified
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <65.0
- cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*range: <60.5
- (no CPE)range: <65
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- osv-coords55 versionspkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/mozilla-nss&distro=openSUSE%20Leap%2015.0
< 60.5.0esr-109.58.3+ 54 more
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 92.0-1.2
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 91.1.1-1.1
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 60.5.1-79.1
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 3.41.1-3.13.1
- (no CPE)range: < 60.5.0-3.24.2
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0-3.20.2
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60.5.0esr-109.58.3
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 3.41.1-58.25.1
- (no CPE)range: < 60-32.5.1
- (no CPE)range: < 60.8.0-lp150.3.62.1
- (no CPE)range: < 3.41.1-lp150.2.20.1
Patches
Vulnerability mechanics
References
17- www.securityfocus.com/bid/106781nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2019:0218nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:0219nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:0269nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:0270nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/01/msg00025.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/02/msg00024.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201903-04nvdThird Party Advisory
- usn.ubuntu.com/3874-1/nvdThird Party Advisory
- usn.ubuntu.com/3897-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4376nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4392nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2019-01/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2019-02/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2019-03/nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2019-07/msg00021.htmlnvd
- security.gentoo.org/glsa/201904-07nvd
News mentions
0No linked articles in our index yet.