CISA Known Exploited Vulnerability

CVE-2024-9680 Ransomware

Mozilla · Firefox

Mozilla Firefox Use-After-Free Vulnerability

Date added
BOD 22-01 due date
CWE CWE-416
Ransomware Known

CISA description

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.