Umbra Wiki cve cve/CVE-2024-9680
Back to wiki

CVE-2024-9680 — Mozilla Firefox Use-After-Free Vulnerability

provenance: imported · CVE: CVE-2024-9680

CVE-2024-9680: Mozilla Firefox Use-After-Free Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Mozilla
Product Firefox
Date added 2024-10-15
Due date 2024-11-05
Ransomware campaign use Known

Description

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-9680

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-9680
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog