CVE-2019-11707 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 37.7% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-13.
Description
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 37.7% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-843 |
| On CISA KEV | yes — remediate by 2022-06-13 |
| Public exploit | yes |
| Published | 2019-07-23 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Mozilla Firefox and Thunderbird Type Confusion Vulnerability |
|---|---|
| Added | 2022-05-23 |
| Due | 2022-06-13 |
| Vendor / product | Mozilla / Firefox and Thunderbird |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | thunderbird |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox 67 - Array.pop JIT Type Confusion | 2022-02-02 |
| exploit-db | Mozilla Spidermonkey - IonMonkey 'Array.prototype.pop' Type Confusion | 2019-06-26 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1544386
- https://security.gentoo.org/glsa/201908-12
- https://www.mozilla.org/security/advisories/mfsa2019-18/
- https://www.mozilla.org/security/advisories/mfsa2019-20/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1544386
- https://security.gentoo.org/glsa/201908-12
- https://www.mozilla.org/security/advisories/mfsa2019-18/
- https://www.mozilla.org/security/advisories/mfsa2019-20/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11707
→ the Explorer · watch your stack · NVD