CVE-2019-11707
ENISA EUVD: EUVD-2019-3377 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 5, 2026
3 articles
EPSS Score
Source: FIRST.org · 2026-05-24
84.29%
probability
This CVE has a 84.29% probability
of being exploited in the next 30 days.
0%
Top 99.3th percentile of all CVEs
100%
CVSS v3.1
Source: NVD8.8
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Project ZeroType confusion in Array.pop
Affected Products
Attack Intelligence
Google Project Zero
Patched
June 18, 2019
Reported by
Samuel Groß of Google Project Zero, Coinbase Security
Root Cause Analysis
https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2019/CVE-2019-11707.html
Exploits & PoC
vigneshsrao/CVE-2019-11707
Exploit code for CVE-2019-11707 on Firefox 66.0.3 running on Ubuntu
42
flabbergastedbd/cve-2019-11707
https://bugs.chromium.org/p/project-zero/issues/detail?id=1820
2
CosminGGeorgescu/CVE-2019-11707-PoC
Proof of concept for CVE-2019-11707
0
3 repos — triés par ⭐
Rechercher sur GitHub ↗
Mozilla Firefox 67.0.3 Patches Actively Exploited Zero-Day
BleepingComputer
Jun 18, 2019
Firefox 0-day Used in Targeted Attacks Against Cryptocurrency Firms
BleepingComputer
Jun 20, 2019
Signal Intelligence
Confidence
95%
EPSS
84.29%
CVSS v3.1
8.8
Mentions
3
Last Seen
Jun 20, 2019
CNA Information
Analyst Note
Auto-imported from Google Project Zero — confirmed zero-day by definition.
Triage Info
Decided atMar 05, 2026