CVE-2019-17026
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.
- Affected products
- Alt Linux, Centos, Firefox, Firefox Esr, Red Hat, Suse, Thunderbird, Ubuntu
- Mozilla Firefox
- < 68.4.1, 72.0.1
- Mozilla Thunderbird
- < 68.4.1
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 46.6% (99th percentile)
- Weakness
- CWE-843
- NVD status
- Analyzed
- Published
- 2020-03-02
CVE-2019-17026 at NVD
9 known exploits for CVE-2019-17026
Proof-of-concept code and exploit modules indexed by Sploitus
DoubleStar
CVE-2019-17026
CVE-2019-17026-Exploit
Mozilla Firefox 67 - Array.pop JIT Type Confusion Exploit
Mozilla Firefox 67 Array.pop JIT Type Confusion
Mozilla Firefox 72 IonMonkey - JIT Type Confusion Exploit
Firefox 72 IonMonkey - JIT Type Confusion
Firefox 72 IonMonkey JIT Type Confusion
Exploit for Type Confusion in Mozilla Firefox