CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2019-11707

Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score96.3720%
EPSS Percentile96.66th
Published2019年7月23日
Last Modified2025年10月27日

Vulnerability Description

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

Affected Platforms (CPE)

📦
Mozilla

Firefox

< 60.7.1
📦
Mozilla

Firefox

< 67.0.3
📦
Mozilla

Thunderbird

< 60.7.2

References & Advisories

相關漏洞威脅