VulnerabilityModified
CVE-2020-15651
This vulnerability affects Firefox for iOS < 28.
MEDIUM 4.3EPSS 0.58%
Does this matter?
Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.
Description
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1649160Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-34/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1649160Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-34/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.