CVE-2024-46964: Code Injection
Published Nov 11, 2024
·Updated
The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.
Affected Software
1 affected component
Unknown All Video Downloader<=11.28
Event History
Nov 11, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-46964?
CVE-2024-46964 is categorized as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-46964?
To fix CVE-2024-46964, update the All Video Downloader application to a version later than 11.28.
3
What type of vulnerability is CVE-2024-46964?
CVE-2024-46964 is a remote code execution vulnerability allowing arbitrary JavaScript code execution.
4
Which applications are affected by CVE-2024-46964?
CVE-2024-46964 affects the All Video Downloader application version 11.28 and earlier.
5
What could an attacker achieve by exploiting CVE-2024-46964?
An attacker exploiting CVE-2024-46964 could execute arbitrary JavaScript code, potentially leading to data theft or device compromise.