CVE-2018-5183: Buffer Overflow
Last updated 25 August 2025
Other sources
Mozilla developers backported selected changes in the Skia library to the ESR52 branch of Firefox. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations.
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-5183?
CVE-2018-5183 is a vulnerability in Mozilla Firefox ESR, Thunderbird, and Thunderbird ESR that allows memory corruption issues, including invalid buffer reads and writes during graphic operations.
Which software versions are affected by CVE-2018-5183?
CVE-2018-5183 affects Thunderbird ESR versions below 52.8, Thunderbird versions below 52.8, and Firefox ESR versions below 52.8.
What is the severity of CVE-2018-5183?
CVE-2018-5183 has a severity rating of critical.
How can I fix CVE-2018-5183?
To fix CVE-2018-5183, update Thunderbird ESR to version 52.8 or later, update Thunderbird to version 52.8 or later, or update Firefox ESR to version 52.8 or later.
Where can I find more information about CVE-2018-5183?
You can find more information about CVE-2018-5183 at the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1454692), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/), [SecurityFocus](http://www.securityfocus.com/bid/104138).