CVE-2018-12292: Use After Free
Published Jun 13, 2018
·Updated
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
Affected Software
1 affected component
Palemoon Pale Moon<27.9.3
Event History
Jun 13, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12292?
CVE-2018-12292 has a moderate severity rating that could potentially allow arbitrary code execution.
2
How do I fix CVE-2018-12292?
To fix CVE-2018-12292, users should update Pale Moon to version 27.9.3 or later.
3
Which versions of Pale Moon are affected by CVE-2018-12292?
CVE-2018-12292 affects all versions of Pale Moon prior to 27.9.3.
4
What exploitation method is used in CVE-2018-12292?
CVE-2018-12292 can be exploited through a use-after-free vulnerability in DOMProxyHandler.
5
Is CVE-2018-12292 specific to any operating system?
CVE-2018-12292 is not specific to any operating system but rather affects the Pale Moon browser on any OS it runs on.