CVE-2018-18492: Use After Free
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-30/#CVE-2018-18492
Other sources
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18492?
CVE-2018-18492 is a use-after-free vulnerability that can occur after deleting a selection element in Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
How severe is CVE-2018-18492?
CVE-2018-18492 has a severity rating of 9.8 out of 10.
Which software versions are affected by CVE-2018-18492?
Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64 are affected by CVE-2018-18492.
What is the remedy for CVE-2018-18492?
The remedy for CVE-2018-18492 is to update Thunderbird to version 60.4 or later, Firefox ESR to version 60.4 or later, and Firefox to version 64 or later.
Where can I find more information about CVE-2018-18492?
You can find more information about CVE-2018-18492 in the following references: [1] [2] [3].