CRITICAL

CVE-2019-9791

CVSS v3

9.8

CRITICAL

EPSS Score

38.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

Technical details

Published
4/26/2019

Frequently asked questions

What is CVE-2019-9791?

The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

Is CVE-2019-9791 actively exploited?

Active exploitation of CVE-2019-9791 has not been confirmed. The EPSS score is 38.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-9791?

CVE-2019-9791 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-9791 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.