<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:37:47.475166+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:1287</id>
    <title>ALSA-2022:1287 — Important: firefox security update</title>
    <updated>2026-10-02T18:37:48.092344+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>This update upgrades Firefox to version 91.8.0 ESR.</p>
<p>Security Fix(es):</p>
<p>* Mozilla: Use-after-free in NSSToken objects (CVE-2022-1097)</p>
<p>* Mozilla: Out of bounds write due to unexpected WebAuthN Extensions (CVE-2022-28281)</p>
<p>* Mozilla: Memory safety bugs fixed in Firefox 99 and Firefox ESR 91.8 (CVE-2022-28289)</p>
<p>* Mozilla: Use-after-free after VR Process destruction (CVE-2022-1196)</p>
<p>* Mozilla: Use-after-free in DocumentL10n::TranslateDocument (CVE-2022-28282)</p>
<p>* Mozilla: Incorrect AliasSet used in JIT Codegen (CVE-2022-28285)</p>
<p>* Mozilla: Denial of Service via complex regular expressions (CVE-2022-24713)</p>
<p>* Mozilla: iframe contents could be rendered outside the border (CVE-2022-28286)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:1287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-02373</id>
    <title>bdu:2022-02373</title>
    <updated>2026-10-02T18:37:48.092424+00:00</updated>
    <content>bdu:2022-02373</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-02373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-311</id>
    <title>certfr-2022-avi-311 — De multiples vulnérabilités ont été découvertes dans Mozilla Firefox et
Firefox ESR. Certaines d'entre elles permettent…</title>
    <updated>2026-10-02T18:37:48.092441+00:00</updated>
    <content>certfr-2022-avi-311</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-311"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-ag66831</id>
    <title>CLEANSTART-2024-AG66831 — regex is an implementation of regular expressions for the Rust language</title>
    <updated>2026-10-02T18:37:48.092457+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: bat, CleanStart: delta</p>
<p>CVE-2022-24713 affects multiple packages. regex is an implementation of regular expressions for the Rust language. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-ag66831"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234383</id>
    <title>EUVD-2026-234383</title>
    <updated>2026-10-02T18:37:48.092481+00:00</updated>
    <content>EUVD-2026-234383</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24713</id>
    <title>fkie_cve-2022-24713</title>
    <updated>2026-10-02T18:37:48.092492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex crate. Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, it us not recommend to deny known problematic regexes.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-24713"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m5pq-gvj9-9vr8</id>
    <title>GHSA-m5pq-gvj9-9vr8 — Rust's regex crate vulnerable to regular expression denial of service</title>
    <updated>2026-10-02T18:37:48.092521+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: regex</p>
<p>&gt; This is a cross-post of [the official security advisory][advisory]. The official advisory contains a signed version with our PGP key, as well.</p>
<p>[advisory]: https://groups.google.com/g/rustlang-security-announcements/c/NcNNL1Jq7Yw</p>
<p>The Rust Security Response WG was notified that the `regex` crate did not properly limit the complexity of the regular expressions (regex) it parses. An attacker could use this security issue to perform a denial of service, by sending a specially crafted regex to a service accepting untrusted regexes. No known vulnerability is present when parsing untrusted input with trusted regexes.</p>
<p>This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the `regex` crate is used to parse untrusted regexes. Other uses of the `regex` crate are not affected by this vulnerability.</p>
<p>## Overview</p>
<p>The `regex` crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API.</p>
<p>Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m5pq-gvj9-9vr8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-24713</id>
    <title>gsd-2022-24713</title>
    <updated>2026-10-02T18:37:48.092563+00:00</updated>
    <content>gsd-2022-24713</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-24713"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-24713</id>
    <title>msrc_CVE-2022-24713 — Regular expression denial of service in Rust's regex crate</title>
    <updated>2026-10-02T18:37:48.092576+00:00</updated>
    <content>msrc_CVE-2022-24713</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-24713"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1673</id>
    <title>OESA-2023-1673 — firefox security update</title>
    <updated>2026-10-02T18:37:48.092592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS: firefox</p>
<p>Mozilla Firefox is a standalone web browser, designed for standards compliance and performance.  Its functionality can be enhanced via a plethora of extensions.

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.

Security Fix(es):

Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 80, Firefox ESR &amp;lt; 78.2, Thunderbird &amp;lt; 78.2, and Firefox for Android &amp;lt; 80.(CVE-2020-15670)

Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 81, Thunderbird &amp;lt; 78.3, and Firefox ESR &amp;lt; 78.3.(CVE-2020-15673)

Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 81.(CVE-2020-15674)

When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnerability affects F…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:1127-1</id>
    <title>openSUSE-SU-2022:1127-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-02T18:37:48.093010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:1127-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:1283</id>
    <title>RHSA-2022:1283 — Red Hat Security Advisory: firefox security update</title>
    <updated>2026-10-02T18:37:48.093031+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mozilla: Use-after-free in NSSToken objects Mozilla: Use-after-free after VR Process destruction Mozilla: Denial of Service via complex regular expressions Mozilla: Out of bounds write due to unexpected WebAuthN Extensions Mozilla: Use-after-free in DocumentL10n::TranslateDocument Mozilla: Incorrect AliasSet used in JIT Codegen Mozilla: iframe contents could be rendered outside the border Mozilla: Memory safety bugs fixed in Firefox 99 and Firefox ESR 91.8</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:1283"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2022-0013</id>
    <title>RUSTSEC-2022-0013 — Regexes with large repetitions on empty sub-expressions take a very long time to parse</title>
    <updated>2026-10-02T18:37:48.093055+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: regex</p>
<p>The Rust Security Response WG was notified that the `regex` crate did not
properly limit the complexity of the regular expressions (regex) it parses. An
attacker could use this security issue to perform a denial of service, by
sending a specially crafted regex to a service accepting untrusted regexes. No
known vulnerability is present when parsing untrusted input with trusted
regexes.</p>
<p>This issue has been assigned CVE-2022-24713. The severity of this vulnerability
is "high" when the `regex` crate is used to parse untrusted regexes. Other uses
of the `regex` crate are not affected by this vulnerability.</p>
<p>## Overview</p>
<p>The `regex` crate features built-in mitigations to prevent denial of service
attacks caused by untrusted regexes, or untrusted input matched by trusted
regexes. Those (tunable) mitigations already provide sane defaults to prevent
attacks. This guarantee is documented and it's considered part of the crate's
API.</p>
<p>Unfortunately a bug was discovered in the mitigations designed to prevent
untrusted regexes to take an arbitrary amount of time during parsing, and it's
possible to craft regexes that bypass such mitigations. This makes it possible
to perform denial of service attacks by sending specially crafted regexes to
services accepting user-controlled, untrusted regexes.</p>
<p>## Affected versions</p>
<p>All versions of the `regex` crate before or equal to 1.5.4 are affected by this
issue. The fix is include starting from  `regex` 1.5.5.</p>
<p>## Mitigations</p>
<p>We recommend everyone…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2022-0013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2022:1114-1</id>
    <title>SUSE-RU-2022:1114-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-02T18:37:48.093093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2022:1114-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24713</id>
    <title>UBUNTU-CVE-2022-24713</title>
    <updated>2026-10-02T18:37:48.093110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: firefox, Ubuntu:18.04:LTS: thunderbird, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: rust-regex, Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: firefox, Ubuntu:22.04:LTS: rust-regex</p>
<p>regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex crate. Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, it us not recommend to deny known problematic regexes.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24713"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0482</id>
    <title>WID-SEC-W-2022-0482 — Mozilla Firefox, Mozilla Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:37:48.093143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Thunderbird ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, falsche Informationen darzustellen und einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0482"/>
  </entry>
</feed>
