A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
History

Fri, 07 Feb 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-05-23'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 Aug 2024 00:30:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2025-02-07T12:49:56.618Z

Reserved: 2019-05-03T00:00:00.000Z

Link: CVE-2019-11707

cve-icon Vulnrichment

Updated: 2024-08-04T23:03:32.447Z

cve-icon NVD

Status : Modified

Published: 2019-07-23T14:15:15.233

Modified: 2025-02-07T13:15:26.000

Link: CVE-2019-11707

cve-icon Redhat

Severity : Critical

Publid Date: 2019-06-19T00:00:00Z

Links: CVE-2019-11707 - Bugzilla