CVE-2019-11707
Summary
| CVE | CVE-2019-11707 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-23 14:15:00 UTC |
| Updated | 2023-01-31 14:15:00 UTC |
| Description | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2. |
Risk And Classification
EPSS: 0.844280000 probability, percentile 0.993200000 (date 2026-04-01)
CISA KEV: Listed on 2022-05-23; due 2022-06-13; ransomware use Unknown
Problem Types: CWE-843
CISA Known Exploited Vulnerability
| Vendor | Mozilla |
|---|---|
| Product | Firefox and Thunderbird |
| Name | Mozilla Firefox and Thunderbird Type Confusion Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-11707 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security vulnerabilities fixed in Thunderbird 60.7.2 — Mozilla | MISC | www.mozilla.org | Vendor Advisory |
| Security vulnerabilities fixed in Firefox 67.0.3 and Firefox ESR 60.7.1 — Mozilla | MISC | www.mozilla.org | Vendor Advisory |
| Mozilla Firefox: Multiple vulnerabilities (GLSA 201908-12) — Gentoo security | GENTOO | security.gentoo.org | |
| Access Denied | MISC | bugzilla.mozilla.org | Issue Tracking, Permissions Required, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500412 Alpine Linux Security Update for mozjs60
- 500917 Alpine Linux Security Update for firefox-esr
- 501201 Alpine Linux Security Update for mozjs68
- 504782 Alpine Linux Security Update for firefox-esr
- 673432 EulerOS Security Update for mozjs60 (EulerOS-SA-2024-1201)
- 673588 EulerOS Security Update for mozjs60 (EulerOS-SA-2024-1319)
- 673812 EulerOS Security Update for mozjs60 (EulerOS-SA-2024-1181)
- 674109 EulerOS Security Update for mozjs60 (EulerOS-SA-2024-1341)
- 690682 Free Berkeley Software Distribution (FreeBSD) Security Update for mozilla (0cea6e0a-7a39-4dac-b3ec-dbc13d404f76)
- 710148 Gentoo Linux Mozilla Firefox Multiple vulnerabilities (GLSA 201908-12)