CVE-2025-3033
01.04.2025, 13:15
After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 137.0 |
mozilla | thunderbird | 𝑥 < 137.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration