CVE-2024-4765

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

04 Apr 2025, 14:27

Type Values Removed Values Added
First Time Mozilla firefox
Mozilla
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1871109 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1871109 - Issue Tracking
References () https://www.mozilla.org/security/advisories/mfsa2024-21/ - () https://www.mozilla.org/security/advisories/mfsa2024-21/ - Vendor Advisory

21 Nov 2024, 09:43

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1871109 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1871109 -
References () https://www.mozilla.org/security/advisories/mfsa2024-21/ - () https://www.mozilla.org/security/advisories/mfsa2024-21/ -

29 Aug 2024, 21:35

Type Values Removed Values Added
Summary
  • (es) Los manifiestos de las aplicaciones web se almacenaban mediante un hash MD5 inseguro que permitía que una colisión de hash sobrescribiera el manifiesto de otra aplicación. Esto podría haberse aprovechado para ejecutar código arbitrario en el contexto de otra aplicación. *Este problema sólo afecta a Firefox para Android. Otras versiones de Firefox no se ven afectadas.* Esta vulnerabilidad afecta a Firefox &lt; 126.
CWE CWE-327
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

14 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 18:15

Updated : 2025-04-04 14:27


NVD link : CVE-2024-4765

Mitre link : CVE-2024-4765

CVE.ORG link : CVE-2024-4765


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm