CVE-2024-4367
14.05.2024, 18:15
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | 𝑥 < 115.11.0 |
| mozilla | firefox | 𝑥 < 126.0 |
| mozilla | thunderbird | 𝑥 < 115.11.0 |
| debian | debian_linux | 10.0 |
| open-xchange | open-xchange_appsuite_frontend | 𝑥 < 7.10.6 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision10 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision11 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision12 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision13 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision14 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision15 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision16 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision17 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision18 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision19 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision20 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision21 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision22 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision23 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision24 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision25 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision26 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision27 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision28 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision29 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision3 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision30 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision31 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision32 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision33 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision34 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision35 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision36 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision37 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision38 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision39 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision4 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision40 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision41 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision42 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision43 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision44 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision5 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision6 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision7 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision8 |
| open-xchange | open-xchange_appsuite_frontend | 7.10.6:revision9 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||||||||
| firefox-esr |
| ||||||||||||||||
| odoo |
| ||||||||||||||||
| thunderbird |
|
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| mozjs52 |
| ||||||||||
| firefox |
| ||||||||||
| mozjs38 |
| ||||||||||
| mozjs68 |
| ||||||||||
| mozjs78 |
| ||||||||||
| mozjs91 |
| ||||||||||
| mozjs102 |
| ||||||||||
| thunderbird |
|
Common Weakness Enumeration
References