CVE-2020-15650
published 2020-08-10CVE-2020-15650: Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the…
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
0.64%
46.8th percentile
Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < 68.11 | 68.11 |
| mozilla | firefox_esr | >= unspecified < 68.11 | 68.11 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Overwriting local files through malicious file picker application
vendor_redhat·2020-07-28·CVSS 5.5
CVE-2020-15650 [MEDIUM] CWE-552 Mozilla: Overwriting local files through malicious file picker application
Mozilla: Overwriting local files through malicious file picker application
Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
Statement: This issue only affected Firefox for Android. Other operating systems are unaffected.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2020-15650: firefox - Given an installed malicious file picker application, an attacker was able to ov...
vendor_debian·2020·CVSS 5.5
CVE-2020-15650 [MEDIUM] CVE-2020-15650: firefox - Given an installed malicious file picker application, an attacker was able to ov...
Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2020-31: CVE-2020-15650
vendor_mozilla·CVSS 5.5
CVE-2020-15650 [MEDIUM] Mozilla Foundation Security Advisory 2020-31: CVE-2020-15650
Mozilla Foundation Security Advisory 2020-31
CVE: CVE-2020-15650
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 68.11
GHSA
GHSA-7f7j-qhc3-4fvp: Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not acces
ghsa_unreviewed·2022-05-24
CVE-2020-15650 [MEDIUM] GHSA-7f7j-qhc3-4fvp: Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not acces
Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
No detection rules found.
No public exploits indexed.
2020-08-10
Published