← back
CVE-2018-12392

CVE-2018-12392

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 3.4%
exploitation probability
3.4%top 12% of all CVEs
observed exploitation
nono source reports it
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.