Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jx2q-hvww-224r

Опубликовано: 22 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

EPSS

Процентиль: 30%
0.00113
Низкий

7.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 3 лет назад

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

CVSS3: 7.8
nvd
около 3 лет назад

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

CVSS3: 7.8
debian
около 3 лет назад

When downloading an HTML file, if the title of the page was formatted ...

CVSS3: 7.8
fstec
больше 3 лет назад

Уязвимость веб-браузера Firefox, связанная с отсутствием ограничений на загрузку файлов, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 30%
0.00113
Низкий

7.8 High

CVSS3

Дефекты

CWE-434