CVE-2024-4367
CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
PoCs públicas encontradas — 23
githubgithub.com/LOURC0D3/CVE-2024-4367-PoC★ 201githubgithub.com/s4vvysec/CVE-2024-4367-POC★ 58githubgithub.com/Zombie-Kaiser/cve-2024-4367-PoC-fixed★ 12githubgithub.com/spaceraccoon/detect-cve-2024-4367★ 11githubgithub.com/snyk-labs/pdfjs-vuln-demo★ 10githubgithub.com/UnHackerEnCapital/PDFernetRemotelo★ 6githubgithub.com/clarkio/pdfjs-vuln-demo★ 4githubgithub.com/Masamuneee/CVE-2024-4367-Analysis★ 4githubgithub.com/1337rokudenashi/Odoo_PDFjs_CVE-2024-4367.pdf★ 2githubgithub.com/kabiri-labs/CVE-2024-4367-PoC★ 1githubgithub.com/elamani-drawing/CVE-2024-4367-POC-PDFJS★ 1githubgithub.com/pS3ud0RAnD0m/cve-2024-4367-poc★ 1githubgithub.com/avalahEE/pdfjs_disable_eval★ 1githubgithub.com/m0d0ri205/PDFJS★ 0githubgithub.com/0xr2r/CVE-2024-4367★ 0githubgithub.com/xiaoqiesec0x1/CVE-2024-4367-PDF.js-xss★ 0githubgithub.com/J1nKsC/CVE-2024-4367_test★ 0githubgithub.com/PenguinCabinet/CVE-2024-4367-hands-on★ 0githubgithub.com/pedrochalegre7/CVE-2024-4367-pdf-sample★ 0githubgithub.com/VVeakee/CVE-2024-4367★ 0githubgithub.com/BektiHandoyo/cve-pdf-host★ 0githubgithub.com/Bhavyakcwestern/Hacking-pdf.js-vulnerability★ 0cve_referencewww.exploit-db.com/exploits/52273não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://bugzilla.mozilla.org/show_bug.cgi?id=1893645https://cert-portal.siemens.com/productcert/html/ssa-827383.htmlhttps://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/http://seclists.org/fulldisclosure/2024/Aug/30https://github.com/gogs/gogs/issues/7928https://github.com/mozilla/pdf.js/releases/tag/v4.2.67https://lists.debian.org/debian-lts-announce/2024/05/msg00010.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00012.htmlhttps://www.exploit-db.com/exploits/52273https://www.mozilla.org/security/advisories/mfsa2024-21/https://www.mozilla.org/security/advisories/mfsa2024-22/https://www.mozilla.org/security/advisories/mfsa2024-23/