CVE-2018-5186: Buffer Overflow
Last updated 25 August 2025
Other sources
Memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 61.
— Launchpad
Mozilla developers and community members Christian Holler, Jason Kratzer, Jon Coppeard, Randell Jesup, Ronald Crane, and Boris Zbarsky reported memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-5186?
CVE-2018-5186 is considered a high severity vulnerability due to potential memory corruption and arbitrary code execution risks.
How do I fix CVE-2018-5186?
To fix CVE-2018-5186, update to Mozilla Firefox version 61 or later.
Which versions of Firefox are affected by CVE-2018-5186?
CVE-2018-5186 affects all versions of Mozilla Firefox prior to version 61.
Can CVE-2018-5186 be exploited?
Yes, with sufficient effort, CVE-2018-5186 could potentially be exploited to execute arbitrary code.
What operating systems are impacted by CVE-2018-5186?
CVE-2018-5186 impacts multiple operating systems including various versions of Ubuntu and Debian where Firefox versions are below 61.