Lucene search

K
vulnrichmentMozillaVULNRICHMENT:CVE-2024-4765
HistoryMay 14, 2024 - 5:21 p.m.

CVE-2024-4765

2024-05-1417:21:25
mozilla
github.com
2
web application
md5 hash
hash collision
arbitrary code execution
firefox for android
vulnerability
firefox < 126

AI Score

7.7

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application’s manifest. This could have been exploited to run arbitrary code in another application’s context.
This issue only affects Firefox for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 126.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*"
    ],
    "vendor": "mozilla",
    "product": "firefox",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "126",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

7.7

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

total