<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:08:24.686896+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:7672</id>
    <title>ALSA-2025:7672 — Moderate: xdg-utils security update</title>
    <updated>2026-10-03T21:08:24.693491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: xdg-utils</p>
<p>The xdg-utils package is a set of simple scripts that provide basic desktop integration functions for any Free Desktop.</p>
<p>Security Fix(es):</p>
<p>* xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments (CVE-2022-4055)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:7672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-04910</id>
    <title>bdu:2025-04910</title>
    <updated>2026-10-03T21:08:24.693546+00:00</updated>
    <content>bdu:2025-04910</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-04910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0524</id>
    <title>certfr-2025-avi-0524 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
    <updated>2026-10-03T21:08:24.693564+00:00</updated>
    <content>certfr-2025-avi-0524</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-235753</id>
    <title>EUVD-2026-235753</title>
    <updated>2026-10-03T21:08:24.693578+00:00</updated>
    <content>EUVD-2026-235753</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-235753"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-4055</id>
    <title>fkie_cve-2022-4055</title>
    <updated>2026-10-03T21:08:24.693589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-4055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p4jr-wm76-h2v3</id>
    <title>GHSA-p4jr-wm76-h2v3</title>
    <updated>2026-10-03T21:08:24.693610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p4jr-wm76-h2v3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-4055</id>
    <title>gsd-2022-4055</title>
    <updated>2026-10-03T21:08:24.693624+00:00</updated>
    <content>gsd-2022-4055</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-4055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-4055</id>
    <title>msrc_CVE-2022-4055 — When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional head…</title>
    <updated>2026-10-03T21:08:24.693634+00:00</updated>
    <content>msrc_CVE-2022-4055</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-4055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:7672</id>
    <title>RHSA-2025:7672 — Red Hat Security Advisory: xdg-utils security update</title>
    <updated>2026-10-03T21:08:24.693649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:7672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-4055</id>
    <title>UBUNTU-CVE-2022-4055</title>
    <updated>2026-10-03T21:08:24.693664+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: xdg-utils, Ubuntu:18.04:LTS: xdg-utils, Ubuntu:20.04:LTS: xdg-utils, Ubuntu:22.04:LTS: xdg-utils, Ubuntu:24.04:LTS: xdg-utils, Ubuntu:25.10: xdg-utils, Ubuntu:26.04:LTS: xdg-utils</p>
<p>When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-4055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1074</id>
    <title>WID-SEC-W-2025-1074 — Red Hat Enterprise Linux (xdg-utils): Schwachstelle ermöglicht Umgehung von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T21:08:24.693690+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1074"/>
  </entry>
</feed>
