A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4310-1 | firefox-esr security update |
Ubuntu USN |
USN-3778-1 | Firefox vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Mozilla firefox Esr
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-05T08:30:59.824Z
Reserved: 2018-06-14T00:00:00
Link: CVE-2018-12386
No data.
Status : Modified
Published: 2018-10-18T13:29:06.273
Modified: 2025-11-25T17:50:16.803
Link: CVE-2018-12386
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN