Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5p65-3pv7-7gq2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.

A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.

EPSS

Процентиль: 40%
0.00186
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 5 лет назад

A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.

CVSS3: 4.3
nvd
больше 5 лет назад

A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.

CVSS3: 4.3
debian
больше 5 лет назад

A unicode RTL order character in the downloaded file name can be used ...

EPSS

Процентиль: 40%
0.00186
Низкий

Дефекты

CWE-20