CVE-2019-9792 describes a critical vulnerability in the IonMonkey JIT compiler used by Mozilla Firefox, Firefox ESR, and Thunderbird, allowing an internal magic value to be leaked during a bailout. This leak can be exploited via JavaScript to achieve memory corruption, leading to a potentially exploitable crash. With a CVSS score of 9.8 (Critical), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not listed on the KEV catalog and with no active exploitation reported, public exploit code exists on ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 60.6.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 66.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 60.6.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.