<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:40:02.671023+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:7178</id>
    <title>ALSA-2022:7178 — Important: thunderbird security update</title>
    <updated>2026-10-03T10:40:02.859347+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: thunderbird</p>
<p>Mozilla Thunderbird is a standalone mail and newsgroup client.</p>
<p>This update upgrades Thunderbird to version 102.4.0.</p>
<p>Security Fix(es):</p>
<p>* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack by malicious server administrators (CVE-2022-39249)
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to a device verification attack (CVE-2022-39250)
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack (CVE-2022-39251)
* Mozilla: Same-origin policy violation could have leaked cross-origin URLs (CVE-2022-42927)
* Mozilla: Memory Corruption in JS Engine (CVE-2022-42928)
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to a data corruption issue (CVE-2022-39236)
* Mozilla: Denial of Service via window.print (CVE-2022-42929)
* Mozilla: Memory safety bugs fixed in Firefox ESR 102.4 and Thunderbird 102.4 (CVE-2022-42932)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:7178"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-869</id>
    <title>certfr-2022-avi-869 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Mozilla Thunderbird&lt;/span&gt;. Elles permettent à…</title>
    <updated>2026-10-03T10:40:02.859412+00:00</updated>
    <content>certfr-2022-avi-869</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-yv48715</id>
    <title>CLEANSTART-2024-YV48715 — Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript</title>
    <updated>2026-10-03T10:40:02.859433+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: element-web</p>
<p>Security vulnerability affects the element-web package. Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-yv48715"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-233555</id>
    <title>EUVD-2026-233555</title>
    <updated>2026-10-03T10:40:02.859455+00:00</updated>
    <content>EUVD-2026-233555</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-233555"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39250</id>
    <title>fkie_cve-2022-39250</title>
    <updated>2026-10-03T10:40:02.859467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’ identities. This would lead to the other device trusting/verifying the user identity under the control of the homeserver instead of the intended one. The vulnerability is a bug in the matrix-js-sdk, caused by checking and signing user identities and devices in two separate steps, and inadequately fixing the keys to be signed between those steps. Even though the attack is partly made possible due to the design decision of treating cross-signing user identities as Matrix devices on the server side (with their device ID set to the public part of the user identity key), no other examined implementations were vulnerable. Starting with version 19.7.0, the matrix-js-sdk has been modified to double check that the key signed is the one that was verified instead of just referencing the key by ID. An additional check has been made to report an error when one of the device ID matches a cross-signing key. As this attack requires coordination between a malicious homeserver and an attacker, those who trust their homeservers do not need a particular workaround.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-39250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5w8r-8pgj-5jmf</id>
    <title>GHSA-5w8r-8pgj-5jmf — matrix-js-sdk subject to user impersonation due to key/device identifier confusion in SAS verification</title>
    <updated>2026-10-03T10:40:02.859500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: matrix-js-sdk</p>
<p>## Impact</p>
<p>An attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’ identities, leading to the other device trusting/verifying the user identity under the control of the homeserver instead of the intended one.</p>
<p>The vulnerability is a bug in the matrix-js-sdk, caused by checking and signing user identities and devices in two separate steps, and inadequately fixing the keys to be signed between those steps.</p>
<p>Even though the attack is partly made possible due to the design decision of treating cross-signing user identities as Matrix devices on the server side (with their device ID set to the public part of the user identity key), no other examined implementations were vulnerable.</p>
<p>## Patches</p>
<p>The matrix-js-sdk has been modified to double check that the key signed is the one that was verified instead of just referencing the key by ID. An additional check has been made to report an error when one of the device ID matches a cross-signing key.</p>
<p>## Workarounds</p>
<p>As this attack requires coordination between a malicious homeserver and an attacker -- if you trust your homeserver no particular workaround is needed.</p>
<p>As a potential way of detecting compromise, it’s possible to review your device list or the device list of other users for devices with IDs in the form of a base64 cross-signing key (`5XaczGNlfz0bl8R1IX5qn+tBoue2tWJqLMh+SDUuvCk`) instead of cla…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5w8r-8pgj-5jmf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-39250</id>
    <title>gsd-2022-39250</title>
    <updated>2026-10-03T10:40:02.859542+00:00</updated>
    <content>gsd-2022-39250</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-39250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12374-1</id>
    <title>openSUSE-SU-2024:12374-1 — element-desktop-1.11.8-1.1 on GA media</title>
    <updated>2026-10-03T10:40:02.859555+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>element-desktop-1.11.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12374-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7181</id>
    <title>RHSA-2022:7181 — Red Hat Security Advisory: thunderbird security update</title>
    <updated>2026-10-03T10:40:02.859575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mozilla: Matrix SDK bundled with Thunderbird vulnerable to a data corruption issue Mozilla: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack by malicious server administrators Mozilla: Matrix SDK bundled with Thunderbird vulnerable to a device verification attack Mozilla: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack Mozilla: Same-origin policy violation could have leaked cross-origin URLs Mozilla: Memory Corruption in JS Engine Mozilla: Denial of Service via window.print Mozilla: Memory safety bugs fixed in Firefox ESR 102.4 and Thunderbird 102.4</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7181"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39250</id>
    <title>UBUNTU-CVE-2022-39250</title>
    <updated>2026-10-03T10:40:02.859600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: thunderbird, Ubuntu:20.04:LTS: thunderbird, Ubuntu:20.04:LTS: node-matrix-js-sdk, Ubuntu:22.04:LTS: node-matrix-js-sdk, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: node-matrix-js-sdk</p>
<p>Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’ identities. This would lead to the other device trusting/verifying the user identity under the control of the homeserver instead of the intended one. The vulnerability is a bug in the matrix-js-sdk, caused by checking and signing user identities and devices in two separate steps, and inadequately fixing the keys to be signed between those steps. Even though the attack is partly made possible due to the design decision of treating cross-signing user identities as Matrix devices on the server side (with their device ID set to the public part of the user identity key), no other examined implementations were vulnerable. Starting with version 19.7.0, the matrix-js-sdk has been modified to double check that the key signed is the one that was verified instead of just referencing the key by ID. An additional check has been made to report an error when one of the device ID matches a cross-signing key. As this attack requires coordination between a malicious homeserver and an attacker, those who trust their homeservers do not need a particular workaround.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1589</id>
    <title>WID-SEC-W-2022-1589 — Mozilla Thunderbird: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:40:02.859636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Thunderbird ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1589"/>
  </entry>
</feed>
