Vulnerability Description
The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and doesn't adequately sanitize the URI or any extra data passed in the intent by any installed application (with no permissions).
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/actuator/com.solarized.firedown/blob/main/CVE-2024-31974
- https://github.com/actuator/com.solarized.firedown/blob/main/CVE-2024-31974
FAQ
What is CVE-2024-31974?
CVE-2024-31974 is a vulnerability with a CVSS score of 6.3 (MEDIUM). The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarize...
How severe is CVE-2024-31974?
CVE-2024-31974 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-31974?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.