Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27039
HistorySep 21, 2020 - 6:32 a.m.

Remote Code Execution (RCE)

2020-09-2106:32:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

0.001 Low

EPSS

Percentile

40.6%

Firefox is vulnerable to remote code execution (RCE). Files with the .JNLP extension used for “Java web start” applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally.