CVE-2019-9813
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
- Affected products
- Alt Linux, Centos, Firefox, Firefox Esr, Red Hat, Suse, Thunderbird, Ubuntu
- Mozilla Firefox
- < 60.6.1, 66.0.1
- Mozilla Thunderbird
- < 60.6.1
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 7.4% (94th percentile)
- Weakness
- CWE-843
- NVD status
- Modified
- Published
- 2019-04-26
CVE-2019-9813 at NVD
4 known exploits for CVE-2019-9813
Proof-of-concept code and exploit modules indexed by Sploitus
SpiderMonkey - IonMonkey Compiled Code Fails to Update Inferred Property Types (Type Confusion)
SpiderMonkey - IonMonkey Compiled Code Fails to Update Inferred Property Types (Type Confusion)
SpiderMonkey - IonMonkey Compiled Code Fails to Update Inferred Property Types (Type Confusion)
SpiderMonkey IonMonkey Type Confusion