VDB

DEBIAN-CVE-2020-15677

DEBIAN-CVE-2020-15677 PUBLISHED CVSS 6.099999904632568 MEDIUM

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

Risk Scores

CVSS v3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Debian:12thunderbird0, 0, 0
Debian:14thunderbird0, 0, 0
Debian:11firefox-esr0, 0, 0
Debian:13thunderbird0, 0, 0
Debian:11thunderbird0, 0, 0
Debian:13firefox-esr0, 0, 0
Debian:12firefox-esr0, 0, 0
Debian:14firefox-esr0, 0, 0

Timeline

  • Oct 1, 2020 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›