CVE-2019-9816 EXPLOIT
5.9
MEDIUM · CVSS 3.0 · EPSS 6.2% (pctl 93)
Patch early
A public exploit exists.
Description
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Scoring
| CVSS | 5.9 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
| EPSS | 6.15% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-843 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-07-23 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | firefox esr |
| mozilla | thunderbird |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Spidermonkey - IonMonkey Unexpected ObjectGroup in ObjectGroupDispatch Operation | 2019-05-29 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1536768
- https://www.mozilla.org/security/advisories/mfsa2019-13/
- https://www.mozilla.org/security/advisories/mfsa2019-14/
- https://www.mozilla.org/security/advisories/mfsa2019-15/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1536768
- https://www.mozilla.org/security/advisories/mfsa2019-13/
- https://www.mozilla.org/security/advisories/mfsa2019-14/
- https://www.mozilla.org/security/advisories/mfsa2019-15/
→ the Explorer · watch your stack · NVD