CVE-2020-15651: Medium severity firefox vulnerability
Published Jul 28, 2020
·Updated
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension.
Affected Software
4 affected components
All of the following
Mozilla Firefox=28
Apple iOS and iPadOS
Mozilla Firefox<28.0
iPhone OS
Event History
Jul 28, 2020
CVE Published
12:00 AM
Aug 10, 2020
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2020-15651?
The severity of CVE-2020-15651 is classified as medium.
2
How do I fix CVE-2020-15651?
To fix CVE-2020-15651, update Mozilla Firefox to the latest version.
3
What does CVE-2020-15651 exploit?
CVE-2020-15651 exploits a unicode RTL order character in the downloaded file name.
4
Which versions of Firefox are affected by CVE-2020-15651?
Versions of Mozilla Firefox prior to 28.0 are affected by CVE-2020-15651.
5
Can CVE-2020-15651 affect Apple iOS devices?
CVE-2020-15651 primarily affects Mozilla Firefox and does not affect Apple iOS devices directly.