cbcvebase.
CVE-2022-45415
published 2022-12-22

CVE-2022-45415: When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that…

PriorityP433high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.23%
13.9th percentile
When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 107.0-1 (sid)firefox 107.0-1 (sid)
mozillafirefox< 107.0107.0
mozillafirefox
mozillafirefox>= 0 < 107.0+build2-0ubuntu0.18.04.1107.0+build2-0ubuntu0.18.04.1
mozillafirefox>= 0 < 107.0+build2-0ubuntu0.20.04.1107.0+build2-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 107107

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_ubuntu8.1HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.