A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.1. The vulnerability is described as CWE-416 Use After Free NIST CVE-2018-12377. Are we missing a CPE here? Please let us know."] Source: https://nvd.nist.gov/vuln/detail/CVE-2018-12377

