Lucene search

K
cvelistMozillaCVELIST:CVE-2024-4765
HistoryMay 14, 2024 - 5:21 p.m.

CVE-2024-4765

2024-05-1417:21:25
mozilla
www.cve.org
18
web application
md5 hash
manifest
hash collision
arbitrary code execution
firefox for android
vulnerability
firefox version 126

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

9.0%

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application’s manifest. This could have been exploited to run arbitrary code in another application’s context.
This issue only affects Firefox for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 126.

CNA Affected

[
  {
    "product": "Firefox",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "126",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

9.0%