Skip to content
COOEY

EXPOSURES › CVE-2019-11707

CVE-2019-11707

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-11707 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

A type confusion vulnerability in Firefox and Thunderbird's Array.pop function allowed an exploitable crash, listed in CISA's KEV catalog.

This type confusion bug in Mozilla's JavaScript object handling could be exploited to crash the browser, and its inclusion in CISA's KEV catalog confirms active exploitation in the wild. For DIB organizations, this highlights the risk of relying on widely deployed software with known, unpatched vulnerabilities that attackers actively target. The takeaway is to ensure all browsers and email clients are patched to the latest versions and to monitor for exploitation attempts.

Shame score — The vulnerability was actively exploited in the wild (KEV) and affected widely used software, indicating a failure to patch known issues before they were weaponized.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.