5.3
CVSSv3

CVE-2018-5173

Published: 11/06/2018 Updated: 03/08/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 18.04

canonical ubuntu linux 17.10

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

mozilla firefox

Vendor Advisories

USN-3645-1 caused a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed This can be used to obscure the file extension of potentially executable files from user view in the panel Note: the dialog to open the file will show the full, correct filename and whether it is executable or not ...
Mozilla Foundation Security Advisory 2018-11 Security vulnerabilities fixed in Firefox 60 Announced May 9, 2018 Impact critical Products Firefox Fixed in Firefox 60 ...
The filename appearing in the Downloads panel in Firefox before 600 improperly renders some Unicode characters, allowing for the file name to be spoofed This can be used to obscure the file extension of potentially executable files from user view in the panel ...