Back

HIGH

Mozilla: Arbitrary JavaScript execution in PDF.js

Published May 14, 2024

Description

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

Metrics

Weaknesses (1)

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published May 14, 2024
Updated May 12, 2026
Reserved Apr 30, 2024
CISA Vulnrichment
Updated Feb 26, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 14, 2024
GHSA-WGRM-67XF-HHPQ