8.8

CVE-2024-4367

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaFirefox SwEditionesr Version < 115.11.0
MozillaFirefox SwEdition- Version < 126.0
MozillaThunderbird Version < 115.11.0
DebianDebian Linux Version10.0
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Update-
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision10
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision11
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision12
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision13
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision14
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision15
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision16
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision17
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision18
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision19
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision20
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision21
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision22
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision23
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision24
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision25
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision26
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision27
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision28
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision29
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision3
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision30
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision31
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision32
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision33
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision34
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision35
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision36
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision37
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision38
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision39
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision4
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision40
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision41
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision42
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision43
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision44
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision5
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision6
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision7
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision8
Open-xchangeOpen-xchange Appsuite Frontend Version7.10.6 Updaterevision9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 37.17% 0.97
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.6 2.2 3.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-754 Improper Check for Unusual or Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.