Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17026

Опубликовано: 02 мар. 2020
Источник: debian
EPSS Средний

Описание

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed72.0.1-1package
firefox-esrfixed68.4.1esr-1package
thunderbirdfixed1:68.4.1-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-03/#CVE-2019-17026

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-04/#CVE-2019-17026

EPSS

Процентиль: 99%
0.43677
Средний

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 6 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
redhat
больше 6 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
nvd
больше 6 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
github
около 4 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
fstec
больше 6 лет назад

Уязвимость JIT-компилятора IonMonkey браузеров Firefox и Firefox ESR, связанная с доступом к ресурсу через несовместимые типы, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 99%
0.43677
Средний