CVE-2020-15658: Medium severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-15658?
The severity of CVE-2020-15658 is low.
Which software products are affected by CVE-2020-15658?
Mozilla Firefox ESR versions up to 78.1, Mozilla Thunderbird versions up to 78.1, and Mozilla Firefox versions up to 79 are affected by CVE-2020-15658.
How can an attacker exploit CVE-2020-15658?
An attacker can exploit CVE-2020-15658 by cutting off the file ending at an earlier position during a file download, leading to a different file type being downloaded than shown in the dialog.
Is there a solution for CVE-2020-15658?
Yes, updating Mozilla Firefox ESR to version 78.1 or later, Mozilla Thunderbird to version 78.1 or later, and Mozilla Firefox to version 79 or later will fix CVE-2020-15658.
Where can I find more information about CVE-2020-15658?
More information about CVE-2020-15658 can be found at the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1637745), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2020-33/), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2020-30/).