Sploitus

CVE-2020-35112

No indexed exploits for CVE-2020-35112 yet

If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

Mozilla Firefox
< 84.0
Mozilla Firefox Esr
< 78.6.0
Mozilla Thunderbird
< 78.6.0
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
1.3% (67th percentile)
NVD status
Modified
Published
2021-01-07
CVE-2020-35112 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2020-35112 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2020-35112 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.