CVE-2019-11707
HIGH KEVMozilla Firefox < 60.7.1 - Type Confusion
Title source: ruleDescription
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
Exploits (6)
exploitdb
WORKING POC
VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/47038
nomisec
WORKING POC
42 stars
by vigneshsrao · client-side
https://github.com/vigneshsrao/CVE-2019-11707
nomisec
WORKING POC
2 stars
by flabbergastedbd · client-side
https://github.com/flabbergastedbd/cve-2019-11707
nomisec
WORKING POC
by CosminGGeorgescu · client-side
https://github.com/CosminGGeorgescu/CVE-2019-11707-PoC
References (5)
Scores
CVSS v3
8.8
EPSS
0.8443
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-05-23
VulnCheck KEV
2019-06-18
InTheWild.io
2019-06-18
ENISA EUVD
EUVD-2019-3377
CWE
CWE-843
Status
published
Products (3)
mozilla/firefox
< 60.7.1
mozilla/firefox
< 67.0.3
mozilla/thunderbird
< 60.7.2
Published
Jul 23, 2019
KEV Added
May 23, 2022
Tracked Since
Feb 18, 2026