Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11707

Опубликовано: 23 июл. 2019
Источник: debian
EPSS Высокий

Описание

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed67.0.3-1package
firefox-esrfixed60.7.1esr-1package
thunderbirdfixed1:60.7.2-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-18/#CVE-2019-11707

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-20/#CVE-2019-11707

EPSS

Процентиль: 99%
0.8362
Высокий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 6 лет назад

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS3: 8.8
redhat
больше 6 лет назад

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS3: 8.8
nvd
больше 6 лет назад

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

suse-cvrf
больше 6 лет назад

Security update for MozillaFirefox

suse-cvrf
больше 6 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 99%
0.8362
Высокий