Beschreibung
Multiple serious vulnerabilities were found in Mozilla Firefox and Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions.
Below is a complete list of vulnerabilities:
- A vulnerability in register allocation in JavaScript can be exploited remotely via arbitrary reading and writing to execute arbitrary code;
- A vulnerability related to JavaScript JIT compiler can be exploited remotely to bypass security restrictions.
Technical details
Vulnerability (2) results from memory leaks that occur when JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout.
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2018-12386 critical
- CVE-2018-12387 critical
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com
Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!