CVE-2024-4367
HIGHMozilla Firefox < 115.11.0 - Improper Condition Check
Title source: ruleDescription
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Exploits (25)
nomisec
WORKING POC
12 stars
by Zombie-Kaiser · poc
https://github.com/Zombie-Kaiser/cve-2024-4367-PoC-fixed
nomisec
WORKING POC
4 stars
by Masamuneee · poc
https://github.com/Masamuneee/CVE-2024-4367-Analysis
nomisec
WORKING POC
4 stars
by UnHackerEnCapital · poc
https://github.com/UnHackerEnCapital/PDFernetRemotelo
nomisec
NO CODE
2 stars
by 1337rokudenashi · poc
https://github.com/1337rokudenashi/Odoo_PDFjs_CVE-2024-4367.pdf
nomisec
WORKING POC
1 stars
by elamani-drawing · poc
https://github.com/elamani-drawing/CVE-2024-4367-POC-PDFJS
nomisec
WORKING POC
by PenguinCabinet · poc
https://github.com/PenguinCabinet/CVE-2024-4367-hands-on
nomisec
WRITEUP
by Bhavyakcwestern · poc
https://github.com/Bhavyakcwestern/Hacking-pdf.js-vulnerability
exploitdb
WORKING POC
by Milad karimi · pythonremotemultiple
https://www.exploit-db.com/exploits/52273
References (11)
Scores
CVSS v3
8.8
EPSS
0.3461
EPSS Percentile
96.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-754
Status
published
Affected Products (49)
mozilla/firefox
< 115.11.0
mozilla/firefox
< 126.0
mozilla/thunderbird
< 115.11.0
debian/debian_linux
open-xchange/open-xchange_appsuite_frontend
< 7.10.6
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
... and 34 more
Timeline
Published
May 14, 2024
Tracked Since
Feb 18, 2026