CVE-2019-9816 PUBLISHED

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

EPSS 38.25% · 97.2th percentile

Risk Scores

EPSS Score
38.25%
97.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSthunderbird0, 1:60.6.1+build2-0ubuntu0.18.04.1, 1:60.5.1+build2-0ubuntu0.18.04.1
Ubuntu:18.04:LTSmozjs5252.3.1-7fakesync1, 52.3.1-0ubuntu3, 0
Ubuntu:20.04:LTSmozjs520, 52.9.1-1ubuntu3, 52.9.1-1build1
Ubuntu:18.04:LTSmozjs380, 38.8.0~repack1-0ubuntu1, 38.8.0~repack1-0ubuntu4
Ubuntu:16.04:LTSthunderbird1:52.9.1+build3-0ubuntu0.16.04.1, 0, 1:38.3.0+build1-0ubuntu2
Ubuntu:16.04:LTSfirefox51.0.1+build2-0ubuntu0.16.04.1, 62.0+build2-0ubuntu0.16.04.3, 62.0+build2-0ubuntu0.16.04.4
Ubuntu:18.04:LTSfirefox66.0.4+build3-0ubuntu0.18.04.1, 66.0.5+build1-0ubuntu0.18.04.1, 0

Timeline

References

Open in Interactive Console →