Junglewise Threat Intelligence

CVE-2019-11707: Mozilla Firefox and Thunderbird Type Confusion Vulnerability

CVE-2019-11707 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-23

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A type confusion vulnerability exists in Mozilla Firefox and Thunderbird when manipulating JavaScript objects via Array.pop. This flaw can result in an exploitable crash and potential arbitrary code execution.

Affected products

  • Mozilla Firefox ESR < 60.7.1
  • Mozilla Firefox < 67.0.3
  • Mozilla Thunderbird < 60.7.2

Timeline

  • 2019-07-23: disclosed: NVD Published Date
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2019-06-18: patched: Mozilla released security advisories MFSA2019-18 and MFSA2019-20
  • 2019-06-18: exploited: Reported as being exploited in targeted attacks in the wild at time of disclosure

Related threats