← Back to browse · API

CVE-2019-17026

Severity
HIGH
CVSS
8.8
EPSS
0.43677
Risk score
75.49
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2019-7500, GHSA-9M3F-27XQ-X4J5
Products
Mozilla:Firefox ESR unspecified <68.4.1, Mozilla:Firefox and Thunderbird, Mozilla:Firefox unspecified <72.0.1, Mozilla:Thunderbird unspecified <68.4.1
Sources
euvd EUVD-2019-7500
cisa.gov CVE-2019-17026

Description

Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.

References