Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-45415

Опубликовано: 22 дек. 2022
Источник: debian
EPSS Низкий

Описание

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed107.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-47/#CVE-2022-45415

EPSS

Процентиль: 30%
0.00113
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 3 лет назад

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

CVSS3: 7.8
nvd
около 3 лет назад

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

CVSS3: 7.8
github
около 3 лет назад

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

CVSS3: 7.8
fstec
больше 3 лет назад

Уязвимость веб-браузера Firefox, связанная с отсутствием ограничений на загрузку файлов, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 30%
0.00113
Низкий