CVE Database
/

CVE-2020-6797

Back to search

CVE-2020-6797

Published: Mar 2, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating systems are unaffected. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

VendorProductVersions

Mozilla

Thunderbird

affected
unspecified - < 68.5

Mozilla

Firefox

affected
unspecified - < 73
affected
unspecified - < ESR68.5

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now