CVE-2018-12371: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.

Affected products

  • Mozilla Firefox: before 60.1.0 (fixed in 60.1.0); before 61.0 (fixed in 61.0)
  • Mozilla Thunderbird: before 60.0 (fixed in 60.0)

Published 2020-07-09. Last modified 2026-06-17.