CVE-2025-6435

🟡 Monitoruj

Brak rozszerzenia pliku przy zapisie odpowiedzi w Devtools w Firefoxie może prowadzić do uruchomienia złośliwego oprogramowania.

CVSS
8.1
EPSS
0.5%
Exploit
none
Vendor
mozilla
Opis źródłowy (NVD)

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.5%
Opublikowano (NVD)2025-06-24 13:15:24 UTC
Ostatnia modyfikacja (NVD)2026-09-30 18:10:00 UTC
Referencje