Back to Database
Status published
High
CVE-2018-5144
An integer overflow can occur during conversion of text to...
Vulnerability Description
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-5144
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.debian.org/security/2018/dsa-4139
- https://security.gentoo.org/glsa/201810-01
- https://security.gentoo.org/glsa/201811-13
- https://access.redhat.com/errata/RHSA-2018:0527
- https://usn.ubuntu.com/3545-1/
- https://lists.debian.org/debian-lts-announce/2018/03/msg00010.html
- https://www.mozilla.org/security/advisories/mfsa2018-09/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://access.redhat.com/errata/RHSA-2018:0526
- https://lists.debian.org/debian-lts-announce/2018/03/msg00029.html
- https://www.debian.org/security/2018/dsa-4155
- https://access.redhat.com/errata/RHSA-2018:0648
- https://access.redhat.com/errata/RHSA-2018:0647
- https://bugzilla.mozilla.org/show_bug.cgi?id=1440926
- http://www.securitytracker.com/id/1040514
- http://www.securityfocus.com/bid/103384
More from Mozilla
View All →CVE-2025-9187
Memory safety bugs fixed in Firefox 142 and Thunderbird 142
Unknown
0
CVE-2025-9186
Spoofing issue in the Address Bar component of Firefox Focus for Android
Unknown
0
CVE-2025-9185
Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
Unknown
0
CVE-2025-9184
Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
Unknown
0
CVE-2025-9183
Spoofing issue in the Address Bar component
Unknown
0
Affected Vendor
Mozilla
View all reports →Affected Software
Firefox ESR, Thunderbird
Vulnerable Versions:
unspecified
Timeline
Official Publish:
June 11th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.