8.1
CVE-2025-6435
- EPSS 0.39%
- Veröffentlicht 24.06.2025 12:28:04
- Zuletzt bearbeitet 30.09.2026 18:10:00
- Erkennungen
Save as in Devtools could download files without sanitizing the extension
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird Version < 140.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.313 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://bugzilla.mozilla.org/show_bug.cgi?id=1950056
https://www.mozilla.org/security/advisories/mfsa2025-51/
https://bugzilla.mozilla.org/show_bug.cgi?id=1961777
https://www.mozilla.org/security/advisories/mfsa2025-54/