Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2019-9810: Security vulnerabilities fixed in Thunderbird 60.6.1

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

CVE
#vulnerability

Mozilla Foundation Security Advisory 2019-12

Announced

March 25, 2019

Impact

critical

Products

Thunderbird

Fixed in

  • Thunderbird 60.6.1

In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.

#CVE-2019-9810: IonMonkey MArraySlice has incorrect alias information

Reporter

Richard Zhu and Amat Cama via Trend Micro’s Zero Day Initiative

Impact

critical

Description

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow.

References

  • Bug 1537924

#CVE-2019-9813: Ionmonkey type confusion with __proto__ mutations

Reporter

Niklas Baumstark via Trend Micro’s Zero Day Initiative

Impact

critical

Description

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write.

References

  • Bug 1538006

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda