CVE-2024-4367
HIGHDescription
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Is your site exposed to CVE-2024-4367?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | firefox |
| mozilla | thunderbird |
| debian | debian_linux |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
| open-xchange | open-xchange_appsuite_frontend |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-4367? +
How severe is CVE-2024-4367? +
What products are affected by CVE-2024-4367? +
How do I check if I'm vulnerable to CVE-2024-4367? +
Related Vulnerabilities
An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate …
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user …
A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing …
A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables …
An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access …
ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EIP-2) was only …