CVE-2018-5173: Input Validation
Last updated 25 August 2025
Other sources
The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.
— Launchpad
The filename appearing in the Downloads panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is CVE-2018-5173?
CVE-2018-5173 is a vulnerability that allows for the spoofing of file names in the Downloads panel of Mozilla Firefox.
What is the severity of CVE-2018-5173?
CVE-2018-5173 has a severity rating of 5.3 (Medium).
How does CVE-2018-5173 affect Mozilla Firefox?
CVE-2018-5173 affects Mozilla Firefox versions up to but excluding version 60.
How can CVE-2018-5173 be exploited?
CVE-2018-5173 can be exploited by using Unicode characters to create file names that spoof the file extension.
What is the remedy for CVE-2018-5173?
The remedy for CVE-2018-5173 is to update Mozilla Firefox to version 60 or later.