EDB-52273
remotemultiple
Firefox ESR 115.11 - PDF.js Arbitrary JavaScript execution
CVE-2024-4367
Milad karimi4/22/2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.