Lucene search

K
cvelistMitreCVELIST:CVE-2009-3376
HistoryOct 29, 2009 - 2:00 p.m.

CVE-2009-3376

2009-10-2914:00:00
mitre
www.cve.org
2

6.6 Medium

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.6%

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.