CVE-2020-35112

CVSS v3.1 8.8 (High)
88% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.26 % (67th)
0.26% Progress
Affected Products 4
Advisories 13

If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

Weaknesses
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2021-01-07 14:15:12
(3 years ago)
Updated Date
2021-01-12 19:01:18
(3 years ago)

Affected Products

Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Mozilla Firefox prior 84.0 version cpe:2.3:a:mozilla:firefox < 84.0
OR  
  Running on/with
  Mozilla Firefox Esr prior 78.6.0 version cpe:2.3:a:mozilla:firefox_esr < 78.6.0
OR  
  Running on/with
  Mozilla Thunderbird prior 78.6.0 version cpe:2.3:a:mozilla:thunderbird < 78.6.0
OR  
  Running on/with
  Microsoft Windows cpe:2.3:o:microsoft:windows:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...