Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-4765
HistoryMay 14, 2024 - 12:00 a.m.

CVE-2024-4765

2024-05-1400:00:00
ubuntu.com
ubuntu.com
11
cve-2024-4765
md5 hash collision
arbitrary code execution
firefox for android

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

9.0%

Web application manifests were stored by using an insecure MD5 hash which
allowed for a hash collision to overwrite another application’s manifest.
This could have been exploited to run arbitrary code in another
application’s context. This issue only affects Firefox for Android. Other
versions of Firefox are unaffected.
This vulnerability affects Firefox <
126.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap starting with Ubuntu 24.04, the thunderbird package is just a script that installs the Thunderbird snap This only affects android

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

9.0%