CVE-2019-9816 describes a type confusion vulnerability in Mozilla products (Firefox, Firefox ESR, and Thunderbird) that could allow security checks to be bypassed when manipulating JavaScript objects in object groups. This medium-severity vulnerability (CVSS 5.9) has a high integrity impact and requires high attack complexity, though it can be exploited remotely without user interaction. While a proof-of-concept exploit exists for Spidermonkey, the vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default. There is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 67.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 60.7CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 60.7CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.