vendor:
Firefox ESR
by:
Milad Karimi (Ex3ptionaL)
6.1
CVSS
HIGH
Arbitrary Code Execution
94
CWE
Product Name: Firefox ESR
Affected Version From: Firefox ESR 115.11
Affected Version To: Firefox ESR 115.11
Patch Exists: YES
Related CWE: CVE-2024-4367
CPE: a:mozilla:firefox_esr:115.11
Platforms Tested: Windows, Ubuntu
2025
Arbitrary JavaScript Execution in PDF.js in Firefox ESR 115.11
The exploit allows an attacker to execute arbitrary JavaScript code in PDF.js in Firefox ESR version 115.11. By manipulating a crafted PDF file, an attacker can trigger this vulnerability. This exploit is identified as CVE-2024-4367.
Mitigation:
To mitigate this vulnerability, users should update their Firefox ESR to a patched version where this exploit has been fixed.