Aller au contenu
appaloosa scout logo main rounded
MEDIUM 6.5

CVE-2020-15658

EN The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Apps suivies affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
mozilla thunderbird Windows <78.1 cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Voir sur NVD ↗