← Back to browse · API

CVE-2024-9680

Severity
CRITICAL
CVSS
9.8
EPSS
0.23184
Risk score
72.31
CISA KEV
Yes
PoC
No
Published
2024-10-09
Modified
2026-08-04
First seen
2026-08-05
Aliases
EUVD-2024-50087, GHSA-HM3J-QGPW-PJ98
Products
Mozilla:Firefox, Mozilla:Firefox ESR unspecified <115.16.1, Mozilla:Firefox ESR unspecified <128.3.1, Mozilla:Firefox unspecified <131.0.2, Mozilla:Thunderbird unspecified <115.16.0, Mozilla:Thunderbird unspecified <128.3.1, Mozilla:Thunderbird unspecified <131.0.1, debian:debian_linux, mozilla:firefox, mozilla:thunderbird
Sources
cisa.gov CVE-2024-9680
euvd EUVD-2024-50087
nvd CVE-2024-9680

Description

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

References