CVE-2018-18502: Buffer Overflow
Last updated 25 August 2025
Other sources
Mozilla developers and community members Arthur Iakab, Christoph Diehl, Christian Holler, Kalel, Emilio Cobos Álvarez, Cristina Coroiu, Noemi Erli, Natalia Csoregi, Julian Seward, Gary Kwong, Tyson Smith, Yaron Tausky, and Ronald Crane reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 65.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 65 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18502?
CVE-2018-18502 is a memory safety bug present in Firefox 64 that allows attackers to execute arbitrary code.
How severe is CVE-2018-18502?
CVE-2018-18502 has a severity rating of critical with a score of 9 out of 10.
Which software versions are affected by CVE-2018-18502?
CVE-2018-18502 affects Firefox versions up to but not including 65.0.
How can I fix CVE-2018-18502?
To fix CVE-2018-18502, update your Firefox browser to version 65.0 or higher.
Where can I find more information about CVE-2018-18502?
You can find more information about CVE-2018-18502 at the following references: [Bugzilla](https://bugzilla.mozilla.org/buglist.cgi?bug_id=1499426%2C1480090%2C1472990%2C1514762%2C1501482%2C1505887%2C1508102%2C1508618%2C1511580%2C1493497%2C1510145%2C1516289%2C1506798%2C1512758), [Mozilla Security Advisories](https://www.mozilla.org/security/advisories/mfsa2019-01/)