CVE-2024-4367

HIGH

Mozilla Firefox < 115.11.0 - Improper Condition Check

Title source: rule

Description

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Exploits (25)

nomisec WORKING POC 191 stars
by LOURC0D3 · poc
https://github.com/LOURC0D3/CVE-2024-4367-PoC
nomisec WORKING POC 57 stars
by s4vvysec · poc
https://github.com/s4vvysec/CVE-2024-4367-POC
nomisec WORKING POC 12 stars
by Zombie-Kaiser · poc
https://github.com/Zombie-Kaiser/cve-2024-4367-PoC-fixed
nomisec SCANNER 11 stars
by spaceraccoon · poc
https://github.com/spaceraccoon/detect-cve-2024-4367
nomisec WORKING POC 8 stars
by snyk-labs · poc
https://github.com/snyk-labs/pdfjs-vuln-demo
nomisec WORKING POC 4 stars
by Masamuneee · poc
https://github.com/Masamuneee/CVE-2024-4367-Analysis
nomisec WORKING POC 4 stars
by clarkio · poc
https://github.com/clarkio/pdfjs-vuln-demo
nomisec WORKING POC 4 stars
by UnHackerEnCapital · poc
https://github.com/UnHackerEnCapital/PDFernetRemotelo
nomisec NO CODE 2 stars
by 1337rokudenashi · poc
https://github.com/1337rokudenashi/Odoo_PDFjs_CVE-2024-4367.pdf
nomisec WORKING POC 2 stars
by exfil0 · poc
https://github.com/exfil0/WEAPONIZING-CVE-2024-4367
nomisec WORKING POC 1 stars
by avalahEE · poc
https://github.com/avalahEE/pdfjs_disable_eval
nomisec WORKING POC 1 stars
by elamani-drawing · poc
https://github.com/elamani-drawing/CVE-2024-4367-POC-PDFJS
nomisec SUSPICIOUS 1 stars
by kabiri-labs · poc
https://github.com/kabiri-labs/CVE-2024-4367-PoC
nomisec WORKING POC 1 stars
by pS3ud0RAnD0m · poc
https://github.com/pS3ud0RAnD0m/cve-2024-4367-poc
nomisec WORKING POC
by VVeakee · poc
https://github.com/VVeakee/CVE-2024-4367
nomisec NO CODE
by BektiHandoyo · poc
https://github.com/BektiHandoyo/cve-pdf-host
nomisec WORKING POC
by m0d0ri205 · poc
https://github.com/m0d0ri205/PDFJS
nomisec WORKING POC
by PenguinCabinet · poc
https://github.com/PenguinCabinet/CVE-2024-4367-hands-on
nomisec NO CODE
by MihranGIT · poc
https://github.com/MihranGIT/POC_CVE-2024-4367
nomisec NO CODE
by pedrochalegre7 · poc
https://github.com/pedrochalegre7/CVE-2024-4367-pdf-sample
nomisec WRITEUP
by Bhavyakcwestern · poc
https://github.com/Bhavyakcwestern/Hacking-pdf.js-vulnerability
nomisec WORKING POC
by 0xr2r · poc
https://github.com/0xr2r/CVE-2024-4367
exploitdb WORKING POC
by Milad karimi · pythonremotemultiple
https://www.exploit-db.com/exploits/52273

Scores

CVSS v3 8.8
EPSS 0.3461
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-754
Status published

Affected Products (49)

mozilla/firefox < 115.11.0
mozilla/firefox < 126.0
mozilla/thunderbird < 115.11.0
debian/debian_linux
open-xchange/open-xchange_appsuite_frontend < 7.10.6
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
open-xchange/open-xchange_appsuite_frontend
... and 34 more

Timeline

Published May 14, 2024
Tracked Since Feb 18, 2026