Skip to main content

CVE detail

CVE-2024-9680

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

CVSS 9.8 · CriticalBuzz score 82.0KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 82.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 7.0
Mention score
30.0
24 evidence mentions in the snapshot
Diversity score
20.0
12 sources across 6 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
7.0
1 repos · best confidence 0.99
Best PoC traction
10
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
24 source links · newest first
  • Russian APT groups intensified attacks against Ukraine and the EU, exploiting zero-day vulnerabilities and deploying wipers, according to ESET. Ukraine faces rising cyber threats The Russia-aligned Sandworm group intensified destructive operations against Ukrainian energy companies, deploying a new wiper named ZEROLOT. Gamaredon remained the most prolific actor targeting Ukraine, enhancing malware obfuscation and introducing PteroBox, a file stealer leveraging Dropbox. “The infamous Sandworm group concentrated heavily on compromising Ukrainian energy infrastructure. In recent cases, it … More →

    newswww.helpnetsecurity.comMay 21, 2025, 4:00 AM
  • 2nd December – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 2nd December, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Supply chain software provider Blue Yonder was hit by a ransomware attack, disrupting services for clients like Starbucks and UK grocery chains Morrisons and Sainsbury’s. The incident affected operations such as employee […]

    vendorresearch.checkpoint.comDec 2, 2024, 11:55 AM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Researchers reveal exploitable flaws in corporate VPN clients Researchers have discovered vulnerabilities in the update process of Palo Alto Networks (CVE-2024-5921) and SonicWall (CVE-2024-29014) corporate VPN clients that could be exploited to remotely execute code on users’ devices. Cybercriminals used a gaming engine to create undetectable malware loader Threat actors are using an ingenious new way for covertly delivering malware … More →

    newswww.helpnetsecurity.comDec 1, 2024, 9:00 AM
  • A Russia-aligned group that engages in both cybercrime and cyberespionage operations used a zero-click exploit chain last month that combined previously unknown and unpatched vulnerabilities in Firefox and Windows. The campaign, whose goal was to deploy the group’s RomCom backdoor on computers, targeted users from Europe and North America. The APT group, also known as […]

    newswww.csoonline.comNov 27, 2024, 6:35 PM
  • The Russia-linked RomCom APT has been observed chaining two zero-days in Firefox and Windows for backdoor delivery.

    newswww.securityweek.comNov 27, 2024, 9:19 AM
  • The Russian RomCom group exploited Firefox and Tor Browser zero-day vulnerabilities in attacks on users in Europe and North America. Russian-based cybercrime group RomCom (aka UAT-5647, Storm-0978, Tropical Scorpius, UAC-0180, UNC2596) exploited two Firefox and Tor Browser zero-day vulnerabilities in recent attacks on users across Europe and North America. The first zero-day exploited by the Russian group, is a use-after-free […]

    newssecurityaffairs.comNov 27, 2024, 8:37 AM
  • Russia-aligned APT group RomCom was behind attacks that leveraged CVE-2024-9680, a remote code execution flaw in Firefox, and CVE-2024-49039, an elevation of privilege vulnerability in Windows Task Scheduler, as zero-days earlier this year. “Chaining together two zero-day vulnerabilities armed RomCom with an exploit that requires no user interaction,” ESET researchers said. The campaign leveraging the zero-click exploit CVE-2024-9680 allowed the attackers to execute code in the restricted context of the browser and CVE-2024-49039 allowed it … More →

    newswww.helpnetsecurity.comNov 26, 2024, 10:00 AM
  • Mozilla warns that a vulnerability in Firefox and Tor Browser is actively being exploited against both browsers

    newswww.malwarebytes.comOct 16, 2024, 11:37 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Windows Kernel, Mozilla Firefox and SolarWinds Web Help Desk bugs to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: An attacker could exploit the vulnerability CVE-2024-30088 to gain SYSTEM privileges. Successful exploitation of […]

    newssecurityaffairs.comOct 16, 2024, 10:48 AM
  • CISA warns that a critical-severity hardcoded credentials vulnerability in SolarWinds Web Help Desk is exploited in attacks.

    newswww.securityweek.comOct 16, 2024, 10:15 AM
  • Tor browser version 13.5.7 is rolling out with patches for an exploited zero-day vulnerability recently addressed in Firefox.

    newswww.securityweek.comOct 14, 2024, 10:43 AM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572) For October 2024 Patch Tuesday, Microsoft has released fixes for 117 security vulnerabilities, including two under active exploitation: CVE-2024-43573, a spoofing bug affecting the Windows MSHTML Platform, and CVE-2024-43572, a remote code execution flaw in the Microsoft Management Console (MMC). SOC teams are frustrated with their security tools Security operations … More →

    newswww.helpnetsecurity.comOct 13, 2024, 8:00 AM
  • Infosec leaders are being warned to make sure employees using the Firefox browser have the latest update installed after the discovery of a critical zero-day vulnerability. The Mozilla Foundation said Wednesday the hole — CVE-2024-9680 — is already being exploited by a threat actor or actors to run code if a user goes to a […]

    newswww.csoonline.comOct 11, 2024, 2:11 AM
  • Mozilla has pushed out an emergency update for its Firefox and Firefox ESR browsers to fix a vulnerability (CVE-2024-9680) that is being exploited in the wild. About CVE-2024-9680 Reported by ESET malware researcher Damien Schaeffer, CVE-2024-9680 is a use-after-free vulnerability in the browser’s Animation timelines and, according to Mozilla, has been exploited to achieve code execution in the content process. Additional details about the vulnerability or the attacks are yet to be shared. According to … More →

    newswww.helpnetsecurity.comOct 10, 2024, 12:29 PM
  • Mozilla has released a Firefox 131 update to resolve CVE-2024-9680, a code execution vulnerability exploited in the wild as a zero-day.

    newswww.securityweek.comOct 10, 2024, 9:17 AM
  • Mozilla released an urgent Firefox update to fix a critical use-after-free vulnerability actively exploited in ongoing attacks. Mozilla released an emergency security update for its Firefox browser to address a critical use-after-free vulnerability, tracked as CVE-2024-9680, that is actively exploited in attacks. The vulnerability CVE-2024-9680 resides in Animation timelines. Firefox Animation Timelines is a feature […]

    newssecurityaffairs.comOct 10, 2024, 7:40 AM
  • No excerpt available.

    Mitigationwww.cisa.govOct 9, 2024, 1:15 PM
  • No excerpt available.

    Vendor Advisorylists.debian.orgOct 9, 2024, 1:15 PM
  • No excerpt available.

    Vendor Advisorylists.debian.orgOct 9, 2024, 1:15 PM
  • No excerpt available.

    Issue Trackingbugs.freebsd.orgOct 9, 2024, 1:15 PM
  • No excerpt available.

    Vendor Advisorywww.mozilla.orgOct 9, 2024, 1:15 PM
  • No excerpt available.

    Vendor Advisorywww.mozilla.orgOct 9, 2024, 1:15 PM
  • No excerpt available.

    Vendor Advisorymsrc.microsoft.comOct 9, 2024, 1:15 PM
  • https://bugzilla.mozilla.org/show_bug.cgi?id=1923344bugzilla.mozilla.org

    No excerpt available.

    Exploitbugzilla.mozilla.orgOct 9, 2024, 1:15 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 10 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence