CVE-2019-11707
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
- Affected products
- Alt Linux, Centos, Firefox, Firefox Esr, Red Hat, Suse, Thunderbird, Tor Browser
- Mozilla Firefox
- < 60.7.1, 67.0.3
- Mozilla Thunderbird
- < 60.7.2
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 37.7% (98th percentile)
- Weakness
- CWE-843
- NVD status
- Analyzed
- Published
- 2019-07-23
CVE-2019-11707 at NVD
11 known exploits for CVE-2019-11707
Proof-of-concept code and exploit modules indexed by Sploitus
cve-2019-11707
CVE-2019-11707
CVE-2019-11707-PoC
Mozilla Firefox 67 - Array.pop JIT Type Confusion Exploit
Mozilla Firefox 67 - Array.pop JIT Type Confusion
Mozilla Firefox 67 Array.pop JIT Type Confusion
Exploit for Type Confusion in Mozilla Firefox
Exploit for Type Confusion in Mozilla Firefox
Mozilla Spidermonkey - IonMonkey (Array.prototype.pop) Type Confusion Exploit
Mozilla Spidermonkey - IonMonkey 'Array.prototype.pop' Type Confusion
Spidermonkey IonMonkey Incorrect Prediction