Lucene search

K
cvelistMozillaCVELIST:CVE-2020-6828
HistoryApr 24, 2020 - 3:48 p.m.

CVE-2020-6828

2020-04-2415:48:22
mozilla
www.cve.org
8

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

45.3%

A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user’s profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary malicious preference values. Control of arbitrary preferences can lead to sufficient compromise such that it is generally equivalent to arbitrary code execution.<br> Note: This issue only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 68.7.

CNA Affected

[
  {
    "product": "Firefox ESR",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "68.7",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

45.3%