{"id":"CVE-2024-4367","details":"A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox \u003c 126, Firefox ESR \u003c 115.11, and Thunderbird \u003c 115.11.","aliases":["GHSA-wgrm-67xf-hhpq"],"modified":"2026-08-14T18:51:36.136740592Z","published":"2024-05-14T17:21:23.486Z","related":["ALSA-2024:2883","ALSA-2024:2888","ALSA-2024:3783","ALSA-2024:3784","ALSA-2026:42062","ALSA-2026:42088","CGA-9prp-5j33-cxv9","SUSE-SU-2024:1676-1","SUSE-SU-2024:1770-1","SUSE-SU-2024:1858-1","SUSE-SU-2026:23111-1","SUSE-SU-2026:23133-1","SUSE-SU-2026:3338-1","SUSE-SU-2026:3396-1","SUSE-SU-2026:3555-1","openSUSE-SU-2024:13980-1","openSUSE-SU-2024:13981-1","openSUSE-SU-2024:14572-1","openSUSE-SU-2026:21508-1"],"database_specific":{"cna_assigner":"mozilla","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/4xxx/CVE-2024-4367.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"126"},{"fixed":"115.11"},{"fixed":"115.11"}]}]},"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Aug/30"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-827383.html"},{"type":"WEB","url":"https://github.com/mozilla/pdf.js/releases/tag/v4.2.67"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/52273"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/4xxx/CVE-2024-4367.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-4367"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-21/"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-22/"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-23/"},{"type":"REPORT","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1893645"},{"type":"REPORT","url":"https://github.com/gogs/gogs/issues/7928"},{"type":"ARTICLE","url":"https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mozilla/pdf.js","events":[{"introduced":"0"},{"fixed":"49b388101a53f1ff81390fab8336d02acf06a582"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v4.1.392","v4.0.379","v4.0.269","v4.0.189","v3.11.174","v3.10.111","v3.9.179","v3.8.162","v3.7.107","v3.6.172","v3.5.141","v3.4.120","v3.3.122","v3.2.146","v3.1.81","v3.0.279","v2.16.105","v2.15.349","v2.14.305","v2.13.216","v2.12.313","v2.11.338","v2.10.377","v2.9.359","v2.8.335","v2.7.570","v2.6.347","v2.5.207","v2.4.456","v2.3.200","v2.2.228","v2.1.266","v2.0.943","v1.10.88","v1.9.426","v1.8.188","v1.8.170","v1.7.225","v1.6.210","v1.5.188","v1.4.20","v1.4.11","v1.3.88","v1.2.109","v1.1.469","v1.1.366","v1.1.215","v1.1.114","v1.1.3","v1.1.1","v1.0.1149","v1.0.1040","v1.0.907","v1.0.712","v1.0.473","v1.0.403","v1.0.277","1.0.277","v1.0.68","v1.0.21","v1.0.2","v0.8.1334","v0.8.1181","v0.5.5","v0.4.11","v0.3.459","v0.1.0","milestone-0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-4367.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}