EUVD-2019-7500
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 3 Nov 2021. Evidence sources: cisa_kev.
- ENISA score
- 8.8 · CVSS 3.1
- Advisory evidence
- 16 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_suse · SUSE-SU-2020:14268-1Security update for MozillaFirefox
- csaf_redhat · RHSA-2020:0127Red Hat Security Advisory: thunderbird security update
- csaf_opensuse · openSUSE-SU-2020:0094-1Security update for MozillaThunderbird
- csaf_redhat · RHSA-2020:0085Red Hat Security Advisory: firefox security update
- csaf_redhat · RHSA-2020:0120Red Hat Security Advisory: thunderbird security update
- csaf_suse · SUSE-SU-2020:0078-1Security update for MozillaFirefox
- csaf_suse · SUSE-SU-2020:0142-1Security update for MozillaThunderbird
- csaf_opensuse · openSUSE-SU-2020:0060-1Security update for MozillaFirefox
- csaf_redhat · RHSA-2020:0111Red Hat Security Advisory: firefox security update
- csaf_redhat · RHSA-2020:0292Red Hat Security Advisory: thunderbird security update
- csaf_suse · SUSE-SU-2020:0068-1Security update for MozillaFirefox
- csaf_redhat · RHSA-2020:0123Red Hat Security Advisory: thunderbird security update
- csaf_redhat · RHSA-2020:0295Red Hat Security Advisory: firefox security update
- csaf_redhat · RHSA-2020:0086Red Hat Security Advisory: firefox security update
