CVE-2023-29541High· 8.8▾ TwilightFirefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating syst…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
0.7% → 0.7%
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
firefox < 112.0firefox_esr < 102.10firefox_mobile < 112.0focus < 112.0thunderbird < 102.10Upgrade past the affected range:
firefox 112.0firefox_esr 102.10firefox_mobile 112.0focus 112.0thunderbird 102.10Connected by shared product, vendor, weakness, or advisory.
CVE-2023-29550High· 8.8Memory safety bugs present in Firefox 111 and Firefox ESR 102.9
CVE-2023-29548Medium· 6.5A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result
CVE-2023-29543High· 8.8An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector
CVE-2023-29539High· 8.8When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character
CVE-2023-29536High· 8.8An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash
CVE-2023-29535Medium· 6.5Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced