CVE-2019-9813 is a high-severity type confusion vulnerability in the IonMonkey JIT compiler affecting Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to 66.0.1 and 60.6.1 respectively. This flaw stems from incorrect handling of __proto__ mutations, which can lead to arbitrary memory read and write capabilities. With a CVSS score of 8.8 (HIGH) and an EPSS score indicating a higher exploitability probability than 97.8% of all CVEs, this vulnerability presents a significant risk. While not listed on CISA's KEV catalog, public exploit code exists on ExploitDB, and it has garnered community discussion, including a Reddit post detailing its use in Pwn2Own.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 60.6.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 66.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 60.6.1CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.