CVE-2019-17026 is a critical type confusion vulnerability in the IonMonkey JIT compiler of Mozilla Firefox and Thunderbird, affecting versions prior to 72.0.1 and 68.4.1 respectively. This flaw carries a CVSS score of 8.8 (High) due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. It is actively exploited in the wild, with exploit code publicly available and significant community discussion, including its use in sophisticated attack chains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 68.4.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 72.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
< 68.4.1CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.