← Back to browse · API

CVE-2024-4367

Severity
MEDIUM
CVSS
5.6
EPSS
0.72648
Risk score
47.83
CISA KEV
No
PoC
Yes
Published
2024-05-14
Modified
2026-05-12
First seen
2026-08-07
Aliases
EUVD-2024-1831, GHSA-WGRM-67XF-HHPQ
Products
Mozilla:Firefox ESR unspecified <115.11, Mozilla:Firefox unspecified <126, Mozilla:Thunderbird unspecified <115.11, debian, linux, redhat, suse
Sources
packetstorm 9dc5d02a903a237e8401a103|CVE-2024-4367
github 13a745e644edda554388774f|CVE-2024-4367
github d840c6d6dd6190b0a376f4b3|CVE-2024-4367
packetstorm dadb44a78e20b90849591a54|CVE-2024-4367
euvd EUVD-2024-1831
packetstorm 4b389f8fbee7077ecf8ae5c9|CVE-2024-4367
packetstorm ad006849554a915da2fdf3cd|CVE-2024-4367
github 1cf1562257b2e0a5531a5521|CVE-2024-4367
packetstorm 6cdbbeb0142a901b7b13ebbe|CVE-2024-4367
packetstorm d1fb40fd94fc8c16fad258b9|CVE-2024-4367

Description

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

References