CVE-2019-11707

HIGH KEV

Mozilla Firefox < 60.7.1 - Type Confusion

Title source: rule

Description

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/47038
exploitdb WORKING POC
by Forrest Orr · textlocalwindows
https://www.exploit-db.com/exploits/50691
nomisec WORKING POC 42 stars
by vigneshsrao · client-side
https://github.com/vigneshsrao/CVE-2019-11707
nomisec WORKING POC 2 stars
by flabbergastedbd · client-side
https://github.com/flabbergastedbd/cve-2019-11707
nomisec WORKING POC
by CosminGGeorgescu · client-side
https://github.com/CosminGGeorgescu/CVE-2019-11707-PoC
inthewild WORKING POC
poc
https://github.com/tunnelshade/cve-2019-11707

Scores

CVSS v3 8.8
EPSS 0.8443
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-05-23
VulnCheck KEV 2019-06-18
InTheWild.io 2019-06-18
ENISA EUVD EUVD-2019-3377
CWE
CWE-843
Status published
Products (3)
mozilla/firefox < 60.7.1
mozilla/firefox < 67.0.3
mozilla/thunderbird < 60.7.2
Published Jul 23, 2019
KEV Added May 23, 2022
Tracked Since Feb 18, 2026