Description
Multiple serious vulnerabilities were found in Mozilla Firefox and Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions.
Below is a complete list of vulnerabilities:
- A vulnerability in register allocation in JavaScript can be exploited remotely via arbitrary reading and writing to execute arbitrary code;
- A vulnerability related to JavaScript JIT compiler can be exploited remotely to bypass security restrictions.
Technical details
Vulnerability (2) results from memory leaks that occur when JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout.
Original advisories
Exploitation
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
Related products
CVE list
- CVE-2018-12386 high
- CVE-2018-12387 high
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com