Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-11707

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.842
EPSS Ranking 99.2%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 7.5
Proposed Action
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
Ransomware Campaign
Unknown
Products affected by CVE-2019-11707


Contact Us

Shodan ® - All rights reserved