CVE-2025-6435

Source
https://cve.org/CVERecord?id=CVE-2025-6435
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6435.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-6435
Downstream
Related
Published
2025-06-24T13:15:24.560Z
Modified
2026-03-14T08:45:37.605044Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the .download file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability affects Firefox < 140 and Thunderbird < 140.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6435.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "140.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "140.0"
            }
        ]
    }
]