Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11707

Опубликовано: 19 июн. 2019
Источник: redhat
CVSS3: 8.8
EPSS Высокий

Описание

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

Отчет

In general, this flaw cannot be exploited through email in Thunderbird because scripting is disabled when reading mail.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=1721789Mozilla: Type confusion in Array.pop

EPSS

Процентиль: 99%
0.81786
Высокий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 6 лет назад

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS3: 8.8
nvd
почти 6 лет назад

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS3: 8.8
debian
почти 6 лет назад

A type confusion vulnerability can occur when manipulating JavaScript ...

suse-cvrf
около 6 лет назад

Security update for MozillaFirefox

suse-cvrf
около 6 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 99%
0.81786
Высокий

8.8 High

CVSS3