Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-9816Type Confusion in Mozilla Firefox

CWE-843Type Confusion15 documents8 sources
Severity
5.9MEDIUMNVD
OSV9.8
EPSS
38.2%
top 2.76%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 23
Latest updateMay 24

Description

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages12 packages

debiandebian/firefox< firefox 67.0-2 (sid)
CVEListV5mozilla/firefoxunspecified67
NVDmozilla/firefox< 67.0
debiandebian/firefox-esr< firefox 67.0-2 (sid)
CVEListV5mozilla/firefox_esrunspecified60.7

🔴Vulnerability Details

6
GHSA
GHSA-w463-rqrr-mc27: A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of se2022-05-24
OSV
CVE-2019-9816: A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of se2019-07-23
OSV
firefox regression2019-06-14
OSV
firefox regression2019-06-06
OSV
thunderbird vulnerabilities2019-05-28

💥Exploits & PoCs

1
Exploit-DB
Spidermonkey - IonMonkey Unexpected ObjectGroup in ObjectGroupDispatch Operation2019-05-29

📋Vendor Advisories

6
Ubuntu
Firefox regression2019-06-14
Ubuntu
Firefox regression2019-06-06
Ubuntu
Thunderbird vulnerabilities2019-05-28
Red Hat
Mozilla: Type confusion with object groups and UnboxedObjects2019-05-22
Ubuntu
Firefox vulnerabilities2019-05-21

💬Community

1
Bugzilla
CVE-2019-9816 Mozilla: Type confusion with object groups and UnboxedObjects2019-05-22