CVE-2019-17026

CVE Published 2020-03-02
Related CWE(s) CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
Related Vendor(s) mozilla, canonical
Related Product(s) thunderbird, ubuntu_linux, firefox, firefox_esr
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

References