Security Advisory

CVE-2023-4581

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-09-11 08:01:45
Last updated 2025-12-18 15:23:06
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.