CVE-2024-9680Critical· 9.8▾ Hadal⚠ Exploited in the wild0dayPoC availableAn attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 4.6 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Nov 5, 2024
Last analysed / modified upstream
23%
3 GitHub repos
Added to the CISA catalog on Oct 15, 2024. Federal remediation due Nov 5, 2024. View catalog ↗
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
firefox < 115.16.1firefox < 131.0.2firefox >= 128.1.0, < 128.3.1thunderbird < 115.16.0thunderbird >= 128.0.1, < 128.3.1thunderbird = 131.0debian_linux = 11.0Upgrade past the affected range:
firefox 128.3.1thunderbird 128.3.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-26485High· 8.8Removing an XSLT parameter during processing could have lead to an exploitable use-after-free
CVE-2022-26486Critical· 9.6An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape
CVE-2026-74943Critical· 9.8Use-after-free in the Graphics: ImageLib component
CVE-2026-74936Critical· 9.8Use-after-free in the JavaScript: WebAssembly component
CVE-2026-74944Critical· 9.8Use-after-free in the DOM: Core & HTML component
CVE-2026-74940Critical· 9.8Use-after-free in the Graphics: Text component