Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 139
A local code execution vulnerability has been identified in the 'Copy as cURL' feature of Mozilla Firefox for Windows, affecting Firefox versions prior to 139, Firefox ESR versions prior to 115.24, and Firefox ESR versions prior to 128.11. The vulnerability arises from inadequate escaping of the ampersand character, which could allow an attacker to manipulate a user into executing a crafted cURL command that executes malicious code on the user's system.
Exploitation of this vulnerability could lead to unauthorized local code execution on the affected user's system.
Users can upgrade to Firefox 139, Firefox ESR 115.24, or Firefox ESR 128.11 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.