CVE-2024-9395: Mozilla Firefox
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.
Affected products
- Mozilla Firefox: before 131.0 (fixed in 131.0)
Published 2024-10-01. Last modified 2026-06-17.