Mozilla: Arbitrary JavaScript execution in PDF.js
Published May 14, 2024
8.8
HIGHCVSS 3.1
EPSS 70.66%
Description
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<126
- Version
-
- Version unspecifiedStatusaffectedConstraints<115.11
- Version
-
- Version unspecifiedStatusaffectedConstraints<115.11
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| ||||||
| Mozilla | Firefox ESR | n/a |
| ||||||
| Mozilla | Thunderbird | n/a |
|
Configuration 1
Configuration 2
- 10.0
Configuration 3
- < 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
-
- Version 0StatusaffectedConstraints<126
- Version
-
- Version 0StatusaffectedConstraints<115.11
- Version
-
- Version 0StatusaffectedConstraints<115.11
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| ||||||
| Mozilla | Firefox Esr | n/a |
| ||||||
| Mozilla | Thunderbird | n/a |
|
Red Hat Enterprise Linux 7
firefox-0:115.11.0-1.el7_9
Fixed · RHSA-2024:2881
Red Hat Enterprise Linux 7
thunderbird-0:115.11.0-1.el7_9
Fixed · RHSA-2024:2913
Red Hat Enterprise Linux 7 Extended Lifecycle Support
webkitgtk4-0:2.52.5-1.el7_9
Fixed · RHSA-2026:58564
Red Hat Enterprise Linux 8
firefox-0:115.11.0-1.el8_10
Fixed · RHSA-2024:3783
Red Hat Enterprise Linux 8
thunderbird-0:115.11.0-1.el8_10
Fixed · RHSA-2024:3784
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.52.5-1.el8_10
Fixed · RHSA-2026:42088
Red Hat Enterprise Linux 8.2 Advanced Update Support
firefox-0:115.11.0-1.el8_2
Fixed · RHSA-2024:2882
Red Hat Enterprise Linux 8.2 Advanced Update Support
thunderbird-0:115.11.0-1.el8_2
Fixed · RHSA-2024:3338
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
firefox-0:115.11.0-1.el8_4
Fixed · RHSA-2024:2886
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
thunderbird-0:115.11.0-1.el8_4
Fixed · RHSA-2024:2911
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
webkit2gtk3-0:2.52.5-1.el8_4
Fixed · RHSA-2026:57348
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
webkit2gtk3-0:2.52.5-1.el8_4
Fixed · RHSA-2026:57348
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
firefox-0:115.11.0-1.el8_4
Fixed · RHSA-2024:2886
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
thunderbird-0:115.11.0-1.el8_4
Fixed · RHSA-2024:2911
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
firefox-0:115.11.0-1.el8_4
Fixed · RHSA-2024:2886
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
thunderbird-0:115.11.0-1.el8_4
Fixed · RHSA-2024:2911
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
webkit2gtk3-0:2.52.5-1.el8_6
Fixed · RHSA-2026:59325
Red Hat Enterprise Linux 8.6 Extended Update Support
firefox-0:115.11.0-1.el8_6
Fixed · RHSA-2024:2887
Red Hat Enterprise Linux 8.6 Extended Update Support
thunderbird-0:115.11.0-1.el8_6
Fixed · RHSA-2024:2912
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
webkit2gtk3-0:2.52.5-1.el8_6
Fixed · RHSA-2026:59325
Red Hat Enterprise Linux 8.8 Extended Update Support
firefox-0:115.11.0-1.el8_8
Fixed · RHSA-2024:2885
Red Hat Enterprise Linux 8.8 Extended Update Support
thunderbird-0:115.11.0-1.el8_8
Fixed · RHSA-2024:2905
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
webkit2gtk3-0:2.52.5-1.el8_8
Fixed · RHSA-2026:59326
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
webkit2gtk3-0:2.52.5-1.el8_8
Fixed · RHSA-2026:59326
Red Hat Enterprise Linux 9
firefox-0:115.11.0-1.el9_4
Fixed · RHSA-2024:2883
Red Hat Enterprise Linux 9
thunderbird-0:115.11.0-1.el9_4
Fixed · RHSA-2024:2888
Red Hat Enterprise Linux 9
webkit2gtk3-0:2.52.5-1.el9_8
Fixed · RHSA-2026:42062
Red Hat Enterprise Linux 9.0 Extended Update Support
firefox-0:115.11.0-1.el9_0
Fixed · RHSA-2024:2884
Red Hat Enterprise Linux 9.0 Extended Update Support
thunderbird-0:115.11.0-1.el9_0
Fixed · RHSA-2024:2904
Red Hat Enterprise Linux 9.2 Extended Update Support
firefox-0:115.11.0-1.el9_2
Fixed · RHSA-2024:2906
Red Hat Enterprise Linux 9.2 Extended Update Support
thunderbird-0:115.11.0-1.el9_2
Fixed · RHSA-2024:2903
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
webkit2gtk3-0:2.52.5-1.el9_2
Fixed · RHSA-2026:58550
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
webkit2gtk3-0:2.52.5-1.el9_4
Fixed · RHSA-2026:54634
Red Hat Enterprise Linux 9.6 Extended Update Support
webkit2gtk3-0:2.52.5-1.el9_6
Fixed · RHSA-2026:54572
Red Hat Enterprise Linux 6
firefox
Out of support scope
Red Hat Enterprise Linux 6
pywebkitgtk
Out of support scope
Red Hat Enterprise Linux 6
thunderbird
Out of support scope
Red Hat Enterprise Linux 6
webkitgtk
Not affected
Red Hat Enterprise Linux 7
webkitgtk3
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | firefox-0:115.11.0-1.el7_9 | Fixed | RHSA-2024:2881 |
| Red Hat Enterprise Linux 7 | thunderbird-0:115.11.0-1.el7_9 | Fixed | RHSA-2024:2913 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | webkitgtk4-0:2.52.5-1.el7_9 | Fixed | RHSA-2026:58564 |
| Red Hat Enterprise Linux 8 | firefox-0:115.11.0-1.el8_10 | Fixed | RHSA-2024:3783 |
| Red Hat Enterprise Linux 8 | thunderbird-0:115.11.0-1.el8_10 | Fixed | RHSA-2024:3784 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.52.5-1.el8_10 | Fixed | RHSA-2026:42088 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | firefox-0:115.11.0-1.el8_2 | Fixed | RHSA-2024:2882 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | thunderbird-0:115.11.0-1.el8_2 | Fixed | RHSA-2024:3338 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | firefox-0:115.11.0-1.el8_4 | Fixed | RHSA-2024:2886 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | thunderbird-0:115.11.0-1.el8_4 | Fixed | RHSA-2024:2911 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | webkit2gtk3-0:2.52.5-1.el8_4 | Fixed | RHSA-2026:57348 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | webkit2gtk3-0:2.52.5-1.el8_4 | Fixed | RHSA-2026:57348 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | firefox-0:115.11.0-1.el8_4 | Fixed | RHSA-2024:2886 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | thunderbird-0:115.11.0-1.el8_4 | Fixed | RHSA-2024:2911 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | firefox-0:115.11.0-1.el8_4 | Fixed | RHSA-2024:2886 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | thunderbird-0:115.11.0-1.el8_4 | Fixed | RHSA-2024:2911 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | webkit2gtk3-0:2.52.5-1.el8_6 | Fixed | RHSA-2026:59325 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | firefox-0:115.11.0-1.el8_6 | Fixed | RHSA-2024:2887 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | thunderbird-0:115.11.0-1.el8_6 | Fixed | RHSA-2024:2912 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | webkit2gtk3-0:2.52.5-1.el8_6 | Fixed | RHSA-2026:59325 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | firefox-0:115.11.0-1.el8_8 | Fixed | RHSA-2024:2885 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | thunderbird-0:115.11.0-1.el8_8 | Fixed | RHSA-2024:2905 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | webkit2gtk3-0:2.52.5-1.el8_8 | Fixed | RHSA-2026:59326 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | webkit2gtk3-0:2.52.5-1.el8_8 | Fixed | RHSA-2026:59326 |
| Red Hat Enterprise Linux 9 | firefox-0:115.11.0-1.el9_4 | Fixed | RHSA-2024:2883 |
| Red Hat Enterprise Linux 9 | thunderbird-0:115.11.0-1.el9_4 | Fixed | RHSA-2024:2888 |
| Red Hat Enterprise Linux 9 | webkit2gtk3-0:2.52.5-1.el9_8 | Fixed | RHSA-2026:42062 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | firefox-0:115.11.0-1.el9_0 | Fixed | RHSA-2024:2884 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | thunderbird-0:115.11.0-1.el9_0 | Fixed | RHSA-2024:2904 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | firefox-0:115.11.0-1.el9_2 | Fixed | RHSA-2024:2906 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | thunderbird-0:115.11.0-1.el9_2 | Fixed | RHSA-2024:2903 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | webkit2gtk3-0:2.52.5-1.el9_2 | Fixed | RHSA-2026:58550 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | webkit2gtk3-0:2.52.5-1.el9_4 | Fixed | RHSA-2026:54634 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | webkit2gtk3-0:2.52.5-1.el9_6 | Fixed | RHSA-2026:54572 |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | pywebkitgtk | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | webkitgtk | Not affected | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Will not fix | n/a |
pdfjs-dist
npm
Introduced 0 Fixed 4.2.67
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | pdfjs-dist | 0 | 4.2.67 |
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
2 other sources (CISA ADP, Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 26, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (64 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 70.66% (0.70660) | 99.38th | v5 (v2026.06.15) |
| Aug 24, 2026 | 70.66% (0.70660) | 99.34th | v5 (v2026.06.15) |
| Jun 15, 2026 | 72.65% (0.72648) | 99.37th | v5 (v2026.06.15) |
| Jun 2, 2026 | 40.32% (0.40321) | 97.42th | v4 (v2025.03.14) |
| May 12, 2026 | 37.76% (0.37762) | 97.25th | v4 (v2025.03.14) |
| Mar 4, 2026 | 34.61% (0.34613) | 96.92th | v4 (v2025.03.14) |
| Mar 1, 2026 | 30.95% (0.30949) | 96.66th | v4 (v2025.03.14) |
| Feb 16, 2026 | 34.61% (0.34613) | 96.90th | v4 (v2025.03.14) |
| Feb 15, 2026 | 32.60% (0.32599) | 96.75th | v4 (v2025.03.14) |
| Feb 4, 2026 | 34.61% (0.34613) | 96.89th | v4 (v2025.03.14) |
| Feb 1, 2026 | 30.95% (0.30949) | 96.64th | v4 (v2025.03.14) |
| Jan 28, 2026 | 33.15% (0.33151) | 96.78th | v4 (v2025.03.14) |
| Jan 4, 2026 | 31.54% (0.31542) | 96.62th | v4 (v2025.03.14) |
| Jan 1, 2026 | 28.03% (0.28032) | 96.34th | v4 (v2025.03.14) |
| Dec 25, 2025 | 31.54% (0.31542) | 96.62th | v4 (v2025.03.14) |
| Dec 4, 2025 | 32.60% (0.32599) | 96.67th | v4 (v2025.03.14) |
| Dec 1, 2025 | 29.03% (0.29032) | 96.41th | v4 (v2025.03.14) |
| Nov 21, 2025 | 33.15% (0.33151) | 96.71th | v4 (v2025.03.14) |
| Nov 18, 2025 | 35.87% (0.35871) | 96.88th | v4 (v2025.03.14) |
| Nov 10, 2025 | 32.60% (0.32599) | 96.65th | v4 (v2025.03.14) |
| Nov 8, 2025 | 35.10% (0.35103) | 96.84th | v4 (v2025.03.14) |
| Nov 5, 2025 | 37.17% (0.37168) | 96.97th | v4 (v2025.03.14) |
| Nov 4, 2025 | 35.10% (0.35103) | 96.83th | v4 (v2025.03.14) |
| Nov 1, 2025 | 31.42% (0.31418) | 96.59th | v4 (v2025.03.14) |
| Oct 22, 2025 | 35.10% (0.35103) | 96.81th | v4 (v2025.03.14) |
| Oct 19, 2025 | 37.17% (0.37168) | 96.95th | v4 (v2025.03.14) |
| Oct 18, 2025 | 35.10% (0.35103) | 96.82th | v4 (v2025.03.14) |
| Oct 4, 2025 | 37.17% (0.37168) | 97.04th | v4 (v2025.03.14) |
| Oct 3, 2025 | 33.40% (0.33403) | 96.80th | v4 (v2025.03.14) |
| Oct 1, 2025 | 28.58% (0.28583) | 96.39th | v4 (v2025.03.14) |
| Sep 4, 2025 | 31.58% (0.31580) | 96.65th | v4 (v2025.03.14) |
| Sep 1, 2025 | 28.07% (0.28068) | 96.33th | v4 (v2025.03.14) |
| Aug 6, 2025 | 31.58% (0.31580) | 96.61th | v4 (v2025.03.14) |
| Aug 4, 2025 | 28.63% (0.28633) | 96.34th | v4 (v2025.03.14) |
| Aug 2, 2025 | 25.30% (0.25299) | 96.01th | v4 (v2025.03.14) |
| Aug 1, 2025 | 28.07% (0.28068) | 96.32th | v4 (v2025.03.14) |
| Jul 20, 2025 | 31.58% (0.31580) | 96.57th | v4 (v2025.03.14) |
| Jul 19, 2025 | 27.81% (0.27812) | 96.23th | v4 (v2025.03.14) |
| Jul 17, 2025 | 30.72% (0.30718) | 96.50th | v4 (v2025.03.14) |
| Jul 4, 2025 | 32.98% (0.32983) | 96.69th | v4 (v2025.03.14) |
| Jul 1, 2025 | 29.40% (0.29397) | 96.39th | v4 (v2025.03.14) |
| Jun 22, 2025 | 32.98% (0.32983) | 96.67th | v4 (v2025.03.14) |
| Jun 16, 2025 | 34.62% (0.34620) | 96.78th | v4 (v2025.03.14) |
| Jun 15, 2025 | 36.58% (0.36579) | 96.91th | v4 (v2025.03.14) |
| Jun 8, 2025 | 15.98% (0.15980) | 94.41th | v4 (v2025.03.14) |
| Jun 6, 2025 | 14.11% (0.14112) | 93.98th | v4 (v2025.03.14) |
| Jun 4, 2025 | 12.42% (0.12421) | 93.53th | v4 (v2025.03.14) |
| Jun 3, 2025 | 9.56% (0.09560) | 92.47th | v4 (v2025.03.14) |
| Jun 1, 2025 | 10.92% (0.10922) | 93.06th | v4 (v2025.03.14) |
| May 20, 2025 | 13.31% (0.13314) | 93.77th | v4 (v2025.03.14) |
| May 4, 2025 | 14.48% (0.14484) | 94.03th | v4 (v2025.03.14) |
| May 3, 2025 | 11.22% (0.11224) | 93.14th | v4 (v2025.03.14) |
| May 1, 2025 | 12.78% (0.12781) | 93.64th | v4 (v2025.03.14) |
| Apr 23, 2025 | 14.48% (0.14484) | 94.02th | v4 (v2025.03.14) |
| Apr 17, 2025 | 31.90% (0.31904) | 96.50th | v4 (v2025.03.14) |
| Apr 15, 2025 | 35.35% (0.35351) | 96.77th | v4 (v2025.03.14) |
| Apr 13, 2025 | 56.87% (0.56867) | 97.95th | v4 (v2025.03.14) |
| Apr 2, 2025 | 55.40% (0.55398) | 97.86th | v4 (v2025.03.14) |
| Mar 23, 2025 | 49.01% (0.49012) | 97.43th | v4 (v2025.03.14) |
| Mar 20, 2025 | 50.27% (0.50265) | 97.63th | v4 (v2025.03.14) |
| Mar 17, 2025 | 49.01% (0.49012) | 97.50th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 12.17th | v3 (v2023.03.01) |
| Jun 11, 2024 | 0.04% (0.00044) | 10.25th | v3 (v2023.03.01) |
| May 15, 2024 | 0.04% (0.00045) | 14.63th | v3 (v2023.03.01) |
References (23)
- http://seclists.org/fulldisclosure/2024/Aug/30 Mailing List
- https://access.redhat.com/security/cve/CVE-2024-4367 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1893645 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=2280382 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-827383.html
- https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js
- https://github.com/advisories/GHSA-wgrm-67xf-hhpq Advisory
- https://github.com/gogs/gogs/issues/7928
- https://github.com/mozilla/pdf.js/commit/85e64b5c16c9aaef738f421733c12911a441cec6
- https://github.com/mozilla/pdf.js/pull/18015
- https://github.com/mozilla/pdf.js/releases/tag/v4.2.67
- https://github.com/mozilla/pdf.js/security/advisories/GHSA-wgrm-67xf-hhpq
- https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html Mailing List
- https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html Mailing List
- https://nvd.nist.gov/vuln/detail/CVE-2024-4367
- https://webkitgtk.org/security/WSA-2026-0004.html
- https://www.cve.org/CVERecord?id=CVE-2024-4367
- https://www.exploit-db.com/exploits/52273
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/#CVE-2024-4367
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/#CVE-2024-4367
- https://www.mozilla.org/security/advisories/mfsa2024-21 Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-22 Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-23 Vendor Advisory
Change history (0)
No recorded changes yet.