A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefox-debuginfoUpgrade firefox | May 4, 2018 | Mar 27, 2018 |
| Debian | — | Upgrade firefox-esr | Feb 19, 2019 | Jun 11, 2018 |
| Freebsd | — | Upgrade linux-firefoxUpgrade seamonkeyUpgrade waterfoxUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade firefox-esrUpgrade firefoxUpgrade linux-thunderbirdUpgrade libxul | Dec 10, 2025 | Mar 27, 2018 |
| Mfsa2018 10 | — | Upgrade to Mozilla Firefox ESR version 52.7.3Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 59.0.2 | Mar 27, 2018 | Mar 26, 2018 |
| Oracle Solaris | — | Upgrade web/data/firefox-bookmarks to version 52.7.3-0.175.3.31.0.4.0 on Solaris 11.3Upgrade web/browser/firefox/plugin/firefox-java to version 52.7.3-0.175.3.31.0.4.0 on Solaris 11.3Upgrade web/browser/firefox to version 52.7.3-0.175.3.31.0.4.0 on Solaris 11.3 | Apr 18, 2018 | Apr 18, 2018 |
| Oracle_linux | — | Upgrade firefox | Mar 2, 2020 | Mar 26, 2018 |
| Redhat_linux | — | No solution existsUpgrade firefox-debuginfoUpgrade firefox | May 1, 2018 | Mar 27, 2018 |
| Suse | — | Upgrade MozillaFirefox-translationsUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-devel | Jun 21, 2018 | Mar 27, 2018 |
| Ubuntu | — | Upgrade firefox | Apr 26, 2018 | Mar 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub