CVE-2019-9810
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
- Affected products
- Alt Linux, Centos, Firefox, Firefox Esr, Red Hat, Suse, Thunderbird, Ubuntu
- Mozilla Firefox
- < 60.6.1, 66.0.1
- Mozilla Thunderbird
- < 60.6.1
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 29.5% (98th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2019-04-26
CVE-2019-9810 at NVD
13 known exploits for CVE-2019-9810
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2019-11708
CVE-2019-9810
CVE-2019-9810-PoC
Exploit for Improper Input Validation in Mozilla Firefox
Exploit for Type Confusion in Mozilla Firefox
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack Exploit
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
Exploit for Improper Input Validation in Mozilla Firefox
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla Firefox
Firefox 66.0.1 - Array.prototype.slice Buffer Overflow Exploit
Firefox Array.prototype.slice Buffer Overflow
Firefox < 66.0.1 - 'Array.prototype.slice' Buffer Overflow