CVE detail
CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 7.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
24 source links · newest first
- Nation-state APTs ramp up attacks on Ukraine and the EUHelp Net Security
Russian APT groups intensified attacks against Ukraine and the EU, exploiting zero-day vulnerabilities and deploying wipers, according to ESET. Ukraine faces rising cyber threats The Russia-aligned Sandworm group intensified destructive operations against Ukrainian energy companies, deploying a new wiper named ZEROLOT. Gamaredon remained the most prolific actor targeting Ukraine, enhancing malware obfuscation and introducing PteroBox, a file stealer leveraging Dropbox. “The infamous Sandworm group concentrated heavily on compromising Ukrainian energy infrastructure. In recent cases, it … More →
newswww.helpnetsecurity.comMay 21, 2025, 4:00 AM - 2nd December – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 2nd December, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Supply chain software provider Blue Yonder was hit by a ransomware attack, disrupting services for clients like Starbucks and UK grocery chains Morrisons and Sainsbury’s. The incident affected operations such as employee […]
vendorresearch.checkpoint.comDec 2, 2024, 11:55 AM - Week in review: Exploitable flaws in corporate VPN clients, malware loader created with gaming engineHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Researchers reveal exploitable flaws in corporate VPN clients Researchers have discovered vulnerabilities in the update process of Palo Alto Networks (CVE-2024-5921) and SonicWall (CVE-2024-29014) corporate VPN clients that could be exploited to remotely execute code on users’ devices. Cybercriminals used a gaming engine to create undetectable malware loader Threat actors are using an ingenious new way for covertly delivering malware … More →
newswww.helpnetsecurity.comDec 1, 2024, 9:00 AM A Russia-aligned group that engages in both cybercrime and cyberespionage operations used a zero-click exploit chain last month that combined previously unknown and unpatched vulnerabilities in Firefox and Windows. The campaign, whose goal was to deploy the group’s RomCom backdoor on computers, targeted users from Europe and North America. The APT group, also known as […]
newswww.csoonline.comNov 27, 2024, 6:35 PMThe Russia-linked RomCom APT has been observed chaining two zero-days in Firefox and Windows for backdoor delivery.
newswww.securityweek.comNov 27, 2024, 9:19 AM- Russian group RomCom exploited Firefox and Tor Browser zero-days to target attacks Europe and North AmericaSecurity Affairs
The Russian RomCom group exploited Firefox and Tor Browser zero-day vulnerabilities in attacks on users in Europe and North America. Russian-based cybercrime group RomCom (aka UAT-5647, Storm-0978, Tropical Scorpius, UAC-0180, UNC2596) exploited two Firefox and Tor Browser zero-day vulnerabilities in recent attacks on users across Europe and North America. The first zero-day exploited by the Russian group, is a use-after-free […]
newssecurityaffairs.comNov 27, 2024, 8:37 AM Russia-aligned APT group RomCom was behind attacks that leveraged CVE-2024-9680, a remote code execution flaw in Firefox, and CVE-2024-49039, an elevation of privilege vulnerability in Windows Task Scheduler, as zero-days earlier this year. “Chaining together two zero-day vulnerabilities armed RomCom with an exploit that requires no user interaction,” ESET researchers said. The campaign leveraging the zero-click exploit CVE-2024-9680 allowed the attackers to execute code in the restricted context of the browser and CVE-2024-49039 allowed it … More →
newswww.helpnetsecurity.comNov 26, 2024, 10:00 AM- Tor Browser and Firefox users should update to fix actively exploited vulnerabilityMalwarebytes Labs
Mozilla warns that a vulnerability in Firefox and Tor Browser is actively being exploited against both browsers
newswww.malwarebytes.comOct 16, 2024, 11:37 AM - U.S. CISA adds Microsoft Windows Kernel, Mozilla Firefox and SolarWinds Web Help Desk bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Windows Kernel, Mozilla Firefox and SolarWinds Web Help Desk bugs to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: An attacker could exploit the vulnerability CVE-2024-30088 to gain SYSTEM privileges. Successful exploitation of […]
newssecurityaffairs.comOct 16, 2024, 10:48 AM CISA warns that a critical-severity hardcoded credentials vulnerability in SolarWinds Web Help Desk is exploited in attacks.
newswww.securityweek.comOct 16, 2024, 10:15 AMTor browser version 13.5.7 is rolling out with patches for an exploited zero-day vulnerability recently addressed in Firefox.
newswww.securityweek.comOct 14, 2024, 10:43 AM- Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security toolsHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572) For October 2024 Patch Tuesday, Microsoft has released fixes for 117 security vulnerabilities, including two under active exploitation: CVE-2024-43573, a spoofing bug affecting the Windows MSHTML Platform, and CVE-2024-43572, a remote code execution flaw in the Microsoft Management Console (MMC). SOC teams are frustrated with their security tools Security operations … More →
newswww.helpnetsecurity.comOct 13, 2024, 8:00 AM Infosec leaders are being warned to make sure employees using the Firefox browser have the latest update installed after the discovery of a critical zero-day vulnerability. The Mozilla Foundation said Wednesday the hole — CVE-2024-9680 — is already being exploited by a threat actor or actors to run code if a user goes to a […]
newswww.csoonline.comOct 11, 2024, 2:11 AMMozilla has pushed out an emergency update for its Firefox and Firefox ESR browsers to fix a vulnerability (CVE-2024-9680) that is being exploited in the wild. About CVE-2024-9680 Reported by ESET malware researcher Damien Schaeffer, CVE-2024-9680 is a use-after-free vulnerability in the browser’s Animation timelines and, according to Mozilla, has been exploited to achieve code execution in the content process. Additional details about the vulnerability or the attacks are yet to be shared. According to … More →
newswww.helpnetsecurity.comOct 10, 2024, 12:29 PMMozilla has released a Firefox 131 update to resolve CVE-2024-9680, a code execution vulnerability exploited in the wild as a zero-day.
newswww.securityweek.comOct 10, 2024, 9:17 AMMozilla released an urgent Firefox update to fix a critical use-after-free vulnerability actively exploited in ongoing attacks. Mozilla released an emergency security update for its Firefox browser to address a critical use-after-free vulnerability, tracked as CVE-2024-9680, that is actively exploited in attacks. The vulnerability CVE-2024-9680 resides in Animation timelines. Firefox Animation Timelines is a feature […]
newssecurityaffairs.comOct 10, 2024, 7:40 AMNo excerpt available.
Mitigationwww.cisa.govOct 9, 2024, 1:15 PMNo excerpt available.
Vendor Advisorylists.debian.orgOct 9, 2024, 1:15 PMNo excerpt available.
Vendor Advisorylists.debian.orgOct 9, 2024, 1:15 PM- https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992bugs.freebsd.org
No excerpt available.
Issue Trackingbugs.freebsd.orgOct 9, 2024, 1:15 PM - https://www.mozilla.org/security/advisories/mfsa2024-52/www.mozilla.org
No excerpt available.
Vendor Advisorywww.mozilla.orgOct 9, 2024, 1:15 PM - https://www.mozilla.org/security/advisories/mfsa2024-51/www.mozilla.org
No excerpt available.
Vendor Advisorywww.mozilla.orgOct 9, 2024, 1:15 PM No excerpt available.
Vendor Advisorymsrc.microsoft.comOct 9, 2024, 1:15 PM- https://bugzilla.mozilla.org/show_bug.cgi?id=1923344bugzilla.mozilla.org
No excerpt available.
Exploitbugzilla.mozilla.orgOct 9, 2024, 1:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.99 · max 10 stars
- moscovium-mc/Tor-0day-JavaScript-ExploitHigh confidencegithubDiscovery source unavailable10 starsDiscovered Jul 9, 2026, 1:19 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-4777CVSS 8.8 · High
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effo…
- CVE-2024-3861CVSS 4.0 · Medium
If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 1…
- CVE-2024-3857CVSS 7.8 · High
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Fi…
- CVE-2024-0746CVSS 6.5 · Medium
A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
- CVE-2023-6859CVSS 8.8 · High
A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
- CVE-2023-6207CVSS 8.8 · High
Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.