CVE-2024-4367
HIGHMozilla Firefox < 115.11.0 - Improper Condition Check
Title source: ruleDescription
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Exploits (26)
exploitdb
WORKING POC
by Milad karimi · pythonremotemultiple
https://www.exploit-db.com/exploits/52273
nomisec
WORKING POC
12 stars
by Zombie-Kaiser · poc
https://github.com/Zombie-Kaiser/cve-2024-4367-PoC-fixed
nomisec
WORKING POC
4 stars
by Masamuneee · poc
https://github.com/Masamuneee/CVE-2024-4367-Analysis
nomisec
WORKING POC
4 stars
by UnHackerEnCapital · poc
https://github.com/UnHackerEnCapital/PDFernetRemotelo
nomisec
NO CODE
2 stars
by 1337rokudenashi · poc
https://github.com/1337rokudenashi/Odoo_PDFjs_CVE-2024-4367.pdf
nomisec
WORKING POC
1 stars
by elamani-drawing · poc
https://github.com/elamani-drawing/CVE-2024-4367-POC-PDFJS
nomisec
WRITEUP
by Bhavyakcwestern · poc
https://github.com/Bhavyakcwestern/Hacking-pdf.js-vulnerability
nomisec
WORKING POC
by PenguinCabinet · poc
https://github.com/PenguinCabinet/CVE-2024-4367-hands-on
References (11)
Scores
CVSS v3
8.8
EPSS
0.3461
EPSS Percentile
97.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-754
Status
published
Products (7)
debian/debian_linux
10.0
mozilla/firefox
< 115.11.0
mozilla/firefox
< 126.0
mozilla/thunderbird
< 115.11.0
npm/pdfjs-dist
0 - 4.2.67npm
open-xchange/open-xchange_appsuite_frontend
7.10.6 (43 CPE variants)
open-xchange/open-xchange_appsuite_frontend
< 7.10.6
Published
May 14, 2024
Tracked Since
Feb 18, 2026