๐Ÿ” CVE Alert

CVE-2023-29541

HIGH 8.8
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.

Vendor mozilla
Product firefox
Ecosystems
Industries
Technology
Published Jun 2, 2023
Last Updated Jan 10, 2025
Stay Ahead of the Next One

Get instant alerts for mozilla firefox

Be the first to know when new high vulnerabilities affecting mozilla firefox are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Mozilla / Firefox
unspecified < 112
Mozilla / Focus for Android
unspecified < 112
Mozilla / Firefox ESR
unspecified < 102.10
Mozilla / Firefox for Android
unspecified < 112
Mozilla / Thunderbird
unspecified < 102.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
mozilla.org: https://www.mozilla.org/security/advisories/mfsa2023-15/ mozilla.org: https://www.mozilla.org/security/advisories/mfsa2023-14/ mozilla.org: https://www.mozilla.org/security/advisories/mfsa2023-13/ bugzilla.mozilla.org: https://bugzilla.mozilla.org/show_bug.cgi?id=1810191