<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T04:52:02.897134+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-24155</id>
    <title>cnvd-2018-24155</title>
    <updated>2026-10-07T04:52:02.902285+00:00</updated>
    <content>cnvd-2018-24155</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-24155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-65621</id>
    <title>EUVD-2026-65621</title>
    <updated>2026-10-07T04:52:02.902327+00:00</updated>
    <content>EUVD-2026-65621</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-65621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-12019</id>
    <title>fkie_cve-2018-12019</title>
    <updated>2026-10-07T04:52:02.902342+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-12019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fc79-j7vw-6xjg</id>
    <title>GHSA-fc79-j7vw-6xjg</title>
    <updated>2026-10-07T04:52:02.902374+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fc79-j7vw-6xjg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-12019</id>
    <title>gsd-2018-12019</title>
    <updated>2026-10-07T04:52:02.902390+00:00</updated>
    <content>gsd-2018-12019</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-12019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10736-1</id>
    <title>openSUSE-SU-2024:10736-1 — enigmail-2.2.4-1.4 on GA media</title>
    <updated>2026-10-07T04:52:02.902401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>enigmail-2.2.4-1.4 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10736-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:2243-1</id>
    <title>SUSE-SU-2018:2243-1 — Security update for enigmail</title>
    <updated>2026-10-07T04:52:02.902421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for enigmail</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:2243-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-12019</id>
    <title>UBUNTU-CVE-2018-12019</title>
    <updated>2026-10-07T04:52:02.902436+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: enigmail, Ubuntu:18.04:LTS: enigmail, Ubuntu:20.04:LTS: enigmail, Ubuntu:22.04:LTS: enigmail</p>
<p>The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-12019"/>
  </entry>
</feed>
