CVE-2018-12407: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Mozilla Firefox: before 64.0 (fixed in 64.0)

Published 2019-02-28. Last modified 2026-06-17.