SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-9791

The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack…

CRITICAL 9.8EPSS 19.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 19.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
19.76% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-843
Affected
mozilla/firefox · mozilla/thunderbird · redhat/enterprise linux · redhat/enterprise linux eus · redhat/enterprise linux server aus · redhat/enterprise linux server tus
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.