CVE-2018-12407: Buffer Overflow
Published Dec 11, 2018
·Updated
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash.
Affected Software
7 affected componentsFixes available
Mozilla Firefox<64.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Mozilla Firefox<64
64
debian/firefox
149.0.2-1
Event History
Dec 11, 2018
CVE Published
12:00 AM
Feb 28, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·10:50 PM
Description
Nov 25, 2025
Data Sourced
via Ubuntu·06:14 PM
RemedyDescriptionSeverityAffected Software
Apr 9, 2026
Data Sourced
via Debian·05:08 PM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2018-12407?
CVE-2018-12407 is a buffer overflow vulnerability in the ANGLE graphics library used for WebGL content in Firefox.
2
Which software is affected by CVE-2018-12407?
Firefox versions lower than 64 are affected by CVE-2018-12407.
3
What is the severity of CVE-2018-12407?
CVE-2018-12407 has a severity rating of 9.8 (Critical).
4
How can the CVE-2018-12407 vulnerability be exploited?
The buffer overflow in the ANGLE graphics library can potentially lead to a crash that may be exploited for malicious purposes.
5
How can I fix CVE-2018-12407?
To fix CVE-2018-12407, update your Firefox browser to version 64 or higher.