Beveiligingsadvies

CVE-2024-31974

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-05-17 15:36:38
Laatst bijgewerkt 2025-02-13 15:48:02
Toegewezen door mitre
CVSS-score 6.3
Status PUBLISHED

Beschrijving

The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and doesn't adequately sanitize the URI or any extra data passed in the intent by any installed application (with no permissions).