CVE-2018-5180: Use After Free
Published May 9, 2018
·Updated
A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited because the memory is freed and reused in a brief window of time during the freeing of the same callstack.
Affected Software
7 affected componentsFixes available
Mozilla Firefox<60.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
Mozilla Firefox<60
60
debian/firefox
148.0-1
Event History
May 9, 2018
CVE Published
12:00 AM
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:06 PM
Description
Nov 29, 2025
Data Sourced
via Ubuntu·06:16 PM
RemedyDescriptionSeverityAffected Software
Feb 27, 2026
Data Sourced
via Debian·12:55 AM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
1
What is the severity of CVE-2018-5180?
The severity of CVE-2018-5180 is high.
2
What software is affected by CVE-2018-5180?
Mozilla Firefox versions < 60 are affected by CVE-2018-5180.
3
How does CVE-2018-5180 occur?
CVE-2018-5180 is a use-after-free vulnerability that can occur during WebGL operations.
4
What is the impact of CVE-2018-5180?
CVE-2018-5180 can result in a potentially exploitable crash.
5
How can I fix CVE-2018-5180?
To fix CVE-2018-5180, update Mozilla Firefox to version 60 or higher.