CISA Known Exploited Vulnerability

CVE-2019-11707

Mozilla · Firefox and Thunderbird

Mozilla Firefox and Thunderbird Type Confusion Vulnerability

Date added
BOD 22-01 due date
CWE CWE-843
Ransomware Unknown

CISA description

Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.

Required action

Apply updates per vendor instructions.