A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| 3d Flipbook Dflip Lite Plugin | 3d-flipbook-dflip-lite-plugin-cve-2024-4367 | May 15, 2025 | May 20, 2024 | |
| Alma_linux | alma-upgrade-firefoxalma-upgrade-firefox-x11alma-upgrade-thunderbird | May 22, 2024 | May 14, 2024 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-firefoxamazon-linux-ami-2-upgrade-firefox-debuginfoamazon-linux-ami-2-upgrade-thunderbirdamazon-linux-ami-2-upgrade-thunderbird-debuginfo | Jun 12, 2024 | May 14, 2024 | |
| Ari Fancy Lightbox Plugin | ari-fancy-lightbox-plugin-cve-2024-4367 | May 15, 2025 | May 20, 2024 | |
| Atlassian Bitbucket | atlassian-bitbucket-upgrade-latest | Mar 19, 2025 | Mar 18, 2025 | |
| Bsk Pdf Manager Plugin | bsk-pdf-manager-plugin-cve-2024-4367 | May 15, 2025 | May 20, 2024 | |
| Centos_linux | — | centos-upgrade-firefoxcentos-upgrade-firefox-debuginfocentos-upgrade-thunderbirdcentos-upgrade-thunderbird-debuginfo | May 17, 2024 | May 14, 2024 |
| Debian | debian-upgrade-firefox-esrdebian-upgrade-odoodebian-upgrade-thunderbird | May 17, 2024 | May 14, 2024 | |
| Embedpress Plugin | embedpress-plugin-cve-2024-4367 | May 15, 2025 | May 20, 2024 | |
| Freebsd | freebsd-upgrade-package-gitlab-cefreebsd-upgrade-package-gitlab-ee | May 23, 2024 | May 22, 2024 | |
| Mfsa2024 21 | mozilla-firefox-upgrade-126_0 | May 15, 2024 | May 14, 2024 | |
| Mfsa2024 22 | mozilla-firefox-esr-upgrade-115_11 | May 15, 2024 | May 14, 2024 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-115_11 | May 15, 2024 | May 15, 2024 | |
| Oracle_linux | — | oracle-linux-upgrade-firefoxoracle-linux-upgrade-firefox-x11oracle-linux-upgrade-thunderbird | May 17, 2024 | May 14, 2024 |
| Pdf Embedder Plugin | pdf-embedder-plugin-cve-2024-4367 | May 15, 2025 | May 20, 2024 | |
| Pdf Poster Plugin | pdf-poster-plugin-cve-2024-4367 | May 15, 2025 | May 20, 2024 | |
| Pdfjs Viewer Shortcode Plugin | pdfjs-viewer-shortcode-plugin-cve-2024-4367 | May 15, 2025 | May 20, 2024 | |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-firefoxredhat-upgrade-firefox-debuginforedhat-upgrade-firefox-debugsourceredhat-upgrade-firefox-x11redhat-upgrade-thunderbirdredhat-upgrade-thunderbird-debuginforedhat-upgrade-thunderbird-debugsource | May 17, 2024 | May 14, 2024 | |
| Rocky_linux | rocky-upgrade-firefoxrocky-upgrade-firefox-debuginforocky-upgrade-firefox-debugsourcerocky-upgrade-thunderbirdrocky-upgrade-thunderbird-debuginforocky-upgrade-thunderbird-debugsource | Jun 17, 2024 | May 14, 2024 | |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | May 20, 2024 | May 14, 2024 |
| Tainacan Plugin | tainacan-plugin-cve-2024-4367 | May 15, 2025 | May 20, 2024 | |
| Ubuntu | ubuntu-upgrade-firefoxubuntu-upgrade-thunderbird | May 28, 2024 | May 14, 2024 | |
| Wonderplugin Pdf Embed Plugin | wonderplugin-pdf-embed-plugin-cve-2024-4367 | May 15, 2025 | May 20, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub