Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c48-vfr3-8jxq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

EPSS

Процентиль: 66%
0.00522
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-754

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 5 лет назад

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVSS3: 6.5
redhat
около 5 лет назад

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVSS3: 6.5
nvd
около 5 лет назад

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVSS3: 6.5
debian
около 5 лет назад

The code for downloading files did not properly take care of special c ...

suse-cvrf
около 5 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 66%
0.00522
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-754