peter bassill · operator
$ cve CVE-2019-11707 JSON

CVE-2019-11707 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 37.7% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-13.

Description

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS37.7% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-843
On CISA KEVyes — remediate by 2022-06-13
Public exploityes
Published2019-07-23
Last modified2026-06-17

CISA KEV

NameMozilla Firefox and Thunderbird Type Confusion Vulnerability
Added2022-05-23
Due2022-06-13
Vendor / productMozilla / Firefox and Thunderbird
Ransomware usenone reported

Affected (2)

VendorProduct
mozillafirefox
mozillathunderbird

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD