← Back

CVE-2024-9393

nvd nist
Published: Oct 1, 2024Modified: Nov 3, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.

Affected (10)

3 products
Firefox
Firefox Esr
Thunderbird
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Before 131.0
Mozilla
Before 115.16.0
From 116.0 to 128.3.0
Mozilla
Before 128.3
Version 129.0 beta2
Version 129.0 beta3
Version 129.0 beta4
Version 129.0 beta5
Version 129.0 beta6
Version 129.0 beta

References (8)

Source: security@mozilla.org
Permissions Required
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.