Описание
Multiple serious vulnerabilities have been found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to obtain sensitive information, cause denial of service, bypass security restrictions and spoof user interface.
Below is a complete list of vulnerabilities:
- Multiple memory corruption vulnerabilities in Skia can be exploited remotely to cause denial of service;
- An information disclosure vulnerability in S/MIME can be exploited locally via chosen-ciphertext attack to obtain sensitive information;
- Multiple use-after-free vulnerabilities can be exploited remotely to cause denial of service;
- An integer overflow and out-of-bounds write vulnerabilities in Skia can be exploited remotely to cause denial of service;
- An unspecified vulnerability can be exploited remotely via specially crafted message headers to obtain sensitive information;
- An unspecified vulnerability can be exploited remotely via src attribute of remote images or links to obtain sensitive information;
- An unspecified vulnerability can be exploited remotely via attachment filename to spoof user interface;
- An unspecified vulnerability can be exploited remotely via specially crafted website to bypass security restrictions;
- A buffer overflow vulnerability can be exploited remotely to cause denial of service.
Первичный источник обнаружения
Эксплуатация
Public exploits exist for this vulnerability.
Связанные продукты
Список CVE
- CVE-2018-5154 critical
- CVE-2018-5155 critical
- CVE-2018-5159 critical
- CVE-2018-5168 warning
- CVE-2018-5174 warning
- CVE-2018-5150 critical
- CVE-2018-5183 critical
- CVE-2018-5184 warning
- CVE-2018-5161 warning
- CVE-2018-5162 warning
- CVE-2018-5170 warning
- CVE-2018-5178 high
- CVE-2018-5185 warning
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!