EIP-2026-117634

PRE-CVE

Mozilla Firefox 3.5.3 - Local Download Manager Temp File Creation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117634. PoCs published by Jeremy Brown.

AI-analyzed exploit summary This exploit leverages a race condition in Mozilla Firefox 3.5.3's download manager to replace a legitimate file with a malicious one by exhausting the filename suffix counter in the /tmp directory. The attack requires write access to /tmp and user interaction to trigger the 'Open with' option.

Description

Mozilla Firefox 3.5.3 - Local Download Manager Temp File Creation

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jeremy Brown · textlocalwindows
https://www.exploit-db.com/exploits/9882

This exploit leverages a race condition in Mozilla Firefox 3.5.3's download manager to replace a legitimate file with a malicious one by exhausting the filename suffix counter in the /tmp directory. The attack requires write access to /tmp and user interaction to trigger the 'Open with' option.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Racy
Target: Mozilla Firefox 3.5.3
No auth needed
Prerequisites: Write access to /tmp directory · Knowledge of the target filename · User interaction to download and open the file
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026