cbcvebase.
CVE-2024-3863
published 2024-04-16

CVE-2024-3863: The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating…

PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.81%
52.9th percentile
The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianfirefox
debianfirefox-esr
debianthunderbird
mozillafirefox< 115.10.0115.10.0
mozillafirefox< 125.0125.0
mozillafirefox
mozillafirefox>= unspecified < 125125
mozillafirefox_esr>= unspecified < 115.10115.10
mozillathunderbird< 115.10115.10
mozillathunderbird>= unspecified < 115.10115.10

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.