CyberzSOC

Publication detail
← Back to advisories & guidance

2024-107: Critical Vulnerability in Firefox ↗ source

October 11, 2024 CERT-EU Advisory

Summary

The vulnerability CVE-2024-9680, with a CVSS score 7.5, could allow an attacker to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. The Mozilla Foundation had reports of this vulnerability being exploited in the wild. CERT-EU strongly recommends upgrading to Firefox 131.0.2, Firefox ESR 115.16.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-9680 9.8 Critical Mozilla Firefox Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.