CVE-2019-9816
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 4.8%
from disclosure to weapon0 days
Published on NVDJul 23
1st PoCMay 29
exploitation probability
4.8%top 9% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
public PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46940⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.