CVE-2019-9795

CRITICAL Year: 2019
CVSS v3 Score
9.8
Critical
CVSS v2 Score
7.5
High

Vulnerability Description

A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS:9.8(Critical)

Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to improper enum values used to check the frame subtype in Snapdr...

CVSS:8.8(High)

Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects ...

CVSS:8.8(High)

stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.

CVSS:8.8(High)

stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.

CVSS:8.8(High)

stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.

CVSS:8.6(High)

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Path Switch Request` message missing a ...