peter bassill · operator
$ cve CVE-2024-9680 JSON

CVE-2024-9680 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 23.2% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2024-11-05.

Description

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS23.18% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2024-11-05
Public exploitnone known
Published2024-10-09
Last modified2026-08-04

CISA KEV

NameMozilla Firefox Use-After-Free Vulnerability
Added2024-10-15
Due2024-11-05
Vendor / productMozilla / Firefox
Ransomware useknown

Affected (3)

VendorProduct
debiandebian linux
mozillafirefox
mozillathunderbird

References

→ the Explorer  ·  watch your stack  ·  NVD