A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
Conclusion & alert: CVE-2019-11707 is rated Critical Active Threat (94.8/100): CVSS High severity, with high exploitation likelihood (EPSS 84.29%, 99th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-05-23) affecting Mozilla / Firefox and Thunderbird. a weakness (CWE-843) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Mozilla Firefox and Thunderbird Type Confusion Vulnerability · CISA KEV detail
: 2022-05-23
: 2022-06-13
: Apply updates per vendor instructions.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 50691 | exploit_db | edb | 2022-02-02 | Exploit-DB ↗ |
| 47038 | exploit_db | edb | 2019-06-26 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-08 | 84.43% | 84.29% | -0.14% |
| 2 | 2026-03-03 | 83.30% | 84.43% | +1.12% |
| 3 | 2026-02-18 | — | 83.30% | — |
Full EPSS history (47 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2019-11707: 2 source package rows (firefox-esr, mozjs60); 10 state rows across 10 repos (3.10-main, 3.11-main, 3.12-main, 3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 10, open 0. | https://security.alpinelinux.org/vuln/CVE-2019-11707 |
debian
|
not yet assigned | CVE-2019-11707 not yet assigned priority: Debian including 3 source packages (firefox, firefox-esr, thunderbird), 11 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 11. | https://security-tracker.debian.org/tracker/CVE-2019-11707 |
gentoo
|
high | CVE-2019-11707: 1 GLSA(s) (201908-12), 2 atom(s) (www-client/firefox, www-client/firefox-bin); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2019-11707 |
redhat
|
critical | — | https://access.redhat.com/security/cve/CVE-2019-11707 |
suse
|
medium | CVE-2019-11707 severity moderate: SUSE including 90 source package names (MozillaFirefox-102.11.0-150200.152.87.1, MozillaFirefox-115.10.0-150200.152.134.1, …), 177 product×package rows across 55 product lines (SUSE Enterprise Storage 4, SUSE Liberty Linux 7, … (55 product lines)): Fixed 177. | https://www.suse.com/security/cve/CVE-2019-11707/ |
ubuntu
|
high | CVE-2019-11707 high priority: Ubuntu including 5 source packages (firefox, mozjs38, mozjs52, mozjs60, thunderbird), 80 status rows across 16 suites (bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, trusty, upstream, xenial): DNE 37, released 30, ignored 11, not-affected 2. | https://ubuntu.com/security/CVE-2019-11707 |
| URL | Tags |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1544386 | Issue Tracking Permissions Required Vendor Advisory |
| https://security.gentoo.org/glsa/201908-12 | Third Party Advisory |
| https://www.mozilla.org/security/advisories/mfsa2019-18/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2019-20/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11707 | US Government Resource |