Description
Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
Published: 2023-09-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-3553-1 firefox-esr security update
Debian DLA Debian DLA DLA-3554-1 thunderbird security update
Debian DSA Debian DSA DSA-5485-1 firefox-esr security update
Debian DSA Debian DSA DSA-5488-1 thunderbird security update
EUVD EUVD EUVD-2023-54435 Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
Ubuntu USN Ubuntu USN USN-6320-1 Firefox vulnerabilities
Ubuntu USN Ubuntu USN USN-6368-1 Thunderbird vulnerabilities
History

Thu, 18 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
Title Mozilla: XLL file extensions were downloadable without warnings XLL file extensions were downloadable without warnings

Thu, 26 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Mozilla Firefox Firefox Esr Thunderbird
Redhat Enterprise Linux Rhel Aus Rhel E4s Rhel Eus Rhel Tus
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2025-12-18T15:23:06.218Z

Reserved: 2023-08-29T03:36:56.674Z

Link: CVE-2023-4581

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:06.542Z

cve-icon NVD

Status : Modified

Published: 2023-09-11T09:15:09.550

Modified: 2024-11-21T08:35:28.540

Link: CVE-2023-4581

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-08-29T00:00:00Z

Links: CVE-2023-4581 - Bugzilla

cve-icon OpenCVE Enrichment

No data.