Security Advisory

CVE-2018-12386

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-10-18 13:00:00
Last updated 2024-08-05 08:30:59
Assigner mozilla
State PUBLISHED

Description

A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.