Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-3033

Опубликовано: 01 апр. 2025
Источник: nvd
CVSS3: 7.7
EPSS Низкий

Описание

After selecting a malicious Windows .url shortcut from the local filesystem, an unexpected file could be uploaded.
This bug only affects Firefox on Windows. Other operating systems are unaffected.. This vulnerability was fixed in Firefox 137 and Thunderbird 137.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Версия до 137.0 (исключая)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Версия до 137.0 (исключая)

EPSS

Процентиль: 7%
0.0017
Низкий

7.7 High

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 1 года назад

After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 137 and Thunderbird 137.

CVSS3: 7.7
debian
больше 1 года назад

After selecting a malicious Windows `.url` shortcut from the local fil ...

CVSS3: 7.7
github
больше 1 года назад

After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137.

CVSS3: 8.1
fstec
больше 1 года назад

Уязвимость браузера Mozilla Firefox и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 7%
0.0017
Низкий

7.7 High

CVSS3

Дефекты

CWE-73