suse · CVE-2018-5155

Quick triage

Priority: high Published: 2021-05-30 14:09:12 UTC Updated: 2026-04-17 15:37:08 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-5155 severity important: SUSE including 95 source package names (MozillaFirefox-102.11.0-150200.152.87.1, MozillaFirefox-115.10.0-150200.152.134.1, …), 196 product×package rows across 61 product lines (HPE Helion OpenStack 8, SUSE Enterprise Storage 4, … (61 product lines)): Fixed 196.

Description:

A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

cvelogic Threat Intelligence