CVE-2019-11707
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash....
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- May 03, 2019
- Published Date
- July 23, 2019
- Last Updated
- February 07, 2025
- Vendor
- Mozilla
- Product
- Firefox ESR, Firefox, Thunderbird
- Description
- A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
CVSS Scores
CVSS v3.1
8.8 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-05-23 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
vigneshsrao/CVE-2019-11707
Type: github • Created: 2019-08-18 07:41:01 UTC • Stars: 42
Exploit code for CVE-2019-11707 on Firefox 66.0.3 running on Ubuntu