7.5
CVSSv3

CVE-2018-5160

Published: 11/06/2018 Updated: 24/08/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 18.04

canonical ubuntu linux 17.10

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

mozilla firefox

Vendor Advisories

USN-3645-1 caused a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash This vulnerability affects Firefox &lt; 60 ...
Mozilla Foundation Security Advisory 2018-11 Security vulnerabilities fixed in Firefox 60 Announced May 9, 2018 Impact critical Products Firefox Fixed in Firefox 60 ...
A uninitialized memory use vulnerability has been found in the WebRTC component of Firefox &lt; 600, which can use a WrappedI420Buffer pixel buffer whose owning image object can be freed while it is still in use This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash ...