CVE-2020-15651 PUBLISHED CVSS 4.300000190734863 MEDIUM

A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.

EPSS 0.19% · 40.2th percentile

Risk Scores

CVSS v3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
0.19%
40.2th percentile

Affected Products

VendorProductVersions
MozillaFirefox for iOSunspecified
mozillafirefox0

Timeline

References

Open in Interactive Console →