CVE-2018-5089: Buffer Overflow
Last updated 25 August 2025
Other sources
Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
— Launchpad
Mozilla developers and community members Christian Holler, Jason Kratzer, Marcia Knous, Nathan Froyd, Oriol Brufau, Ronald Crane, Randell Jesup, Tyson Smith, Emilio Cobos Álvarez, Ryan VanderMeulen, Sebastian Hengst, Karl Tomlinson, Xidorn Quan, Ludovic Hirlimann, and Jason Orendorff reported memory safety bugs present in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Mozilla developers and community members Christian Holler, Jason Kratzer, Marcia Knous, Nathan Froyd, Oriol Brufau, Ronald Crane, Randell Jesup, Tyson Smith, Emilio Cobos Álvarez, Ryan VanderMeulen, Sebastian Hengst, Karl Tomlinson, Xidorn Quan, Ludovic Hirlimann, and Jason Orendorff reported memory safety bugs present in Firefox 57, Firefox ESR 52.5, and Thunderbird 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
— Mozilla
Mozilla developers and community members reported memory safety bugs present in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5089
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5095
- CVE-2018-5096
- CVE-2018-5097
- CVE-2018-5098
- CVE-2018-5099
- CVE-2018-5102
- CVE-2018-5103
- CVE-2018-5104
- CVE-2018-5117
- CVE-2018-5089
- CVE-2018-5091
- CVE-2018-5092
- CVE-2018-5093
- CVE-2018-5094
- CVE-2018-5100
- CVE-2018-5101
- CVE-2018-5105
- CVE-2018-5106
- CVE-2018-5107
- CVE-2018-5108
- CVE-2018-5109
- CVE-2018-5110
- CVE-2018-5111
- CVE-2018-5112
- CVE-2018-5113
- CVE-2018-5114
- CVE-2018-5115
- CVE-2018-5116
- CVE-2018-5118
- CVE-2018-5119
- CVE-2018-5121
- CVE-2018-5122
- CVE-2018-5090
Frequently Asked Questions
What is the severity of CVE-2018-5089?
CVE-2018-5089 has been classified as a high severity vulnerability due to evidence suggesting it could allow arbitrary code execution.
How do I fix CVE-2018-5089?
To fix CVE-2018-5089, update your Firefox or Thunderbird installation to version 52.6 or later.
What versions are affected by CVE-2018-5089?
CVE-2018-5089 affects Firefox versions up to 58.0 and Thunderbird versions up to 52.6.
Is CVE-2018-5089 present in Firefox ESR?
Yes, CVE-2018-5089 affects Firefox ESR versions prior to 52.6.
Can CVE-2018-5089 be exploited for remote attacks?
Yes, with sufficient effort, attackers may exploit CVE-2018-5089 to execute arbitrary code remotely.