File Name Manipulation Vulnerability in Mozilla Firefox for iOS
CVE-2020-15651

4.3MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
10 August 2020

What is CVE-2020-15651?

A file name manipulation vulnerability exists in Mozilla Firefox for iOS that allows an attacker to exploit a unicode RTL order character in the downloaded file name. This weakness can lead to changes in the file's extension during the download process, potentially enabling the execution of malicious files by misleading users about the nature of the file they are downloading. Affected users should upgrade to the latest version of Firefox to mitigate this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Firefox for iOS < 28

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.