6.5
CVSSv3

CVE-2020-15658

Published: 10/08/2020 Updated: 02/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

mozilla firefox esr

mozilla firefox

canonical ubuntu linux 18.04

canonical ubuntu linux 20.04

canonical ubuntu linux 16.04

Vendor Advisories

Synopsis Important: firefox security and bug fix update Type/Severity Security Advisory: Important Topic An update for firefox is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ...
Synopsis Important: firefox security update Type/Severity Security Advisory: Important Topic An update for firefox is now available for Red Hat Enterprise Linux 80 Update Services for SAP SolutionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabili ...
Synopsis Important: firefox security update Type/Severity Security Advisory: Important Topic An update for firefox is now available for Red Hat Enterprise Linux 81 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
Synopsis Important: firefox security update Type/Severity Security Advisory: Important Topic An update for firefox is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, ...
Severity Unknown Remote Unknown Type Unknown Description AVG-1214 thunderbird 68110-1 High Vulnerable AVG-1213 firefox 7802-1 790-1 High Fixed ...
Mozilla Foundation Security Advisory 2020-30 Security Vulnerabilities fixed in Firefox 79 Announced July 28, 2020 Impact high Products Firefox Fixed in Firefox 79 ...
Mozilla Foundation Security Advisory 2020-33 Security Vulnerabilities fixed in Thunderbird 781 Announced July 28, 2020 Impact high Products Thunderbird Fixed in Thunderbird 781 ...
Mozilla Foundation Security Advisory 2020-32 Security Vulnerabilities fixed in Firefox ESR 781 Announced July 28, 2020 Impact high Products Firefox ESR Fixed in Firefox ESR 781 ...