<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:36:21.168659+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:1802</id>
    <title>ALSA-2023:1802 — Important: thunderbird security update</title>
    <updated>2026-10-02T15:36:21.446935+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: thunderbird</p>
<p>Mozilla Thunderbird is a standalone mail and newsgroup client.</p>
<p>This update upgrades Thunderbird to version 102.10.0.</p>
<p>Security Fix(es):</p>
<p>* Thunderbird: Revocation status of S/Mime recipient certificates was not checked (CVE-2023-0547)
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack (CVE-2023-28427)
* Mozilla: Fullscreen notification obscured (CVE-2023-29533)
* Mozilla: Potential Memory Corruption following Garbage Collector compaction (CVE-2023-29535)
* Mozilla: Invalid free from JavaScript code (CVE-2023-29536)
* Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10 (CVE-2023-29550)
* Mozilla: Memory Corruption in Safe Browsing Code (CVE-2023-1945)
* Thunderbird: Hang when processing certain OpenPGP messages (CVE-2023-29479)
* Mozilla: Content-Disposition filename truncation leads to Reflected File Download (CVE-2023-29539)
* Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux (CVE-2023-29541)
* Mozilla: Incorrect optimization result on ARM64 (CVE-2023-29548)
* MFSA-TMP-2023-0001 Mozilla: Double-free in libwebp (BZ#2186102)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:1802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-01835</id>
    <title>bdu:2023-01835</title>
    <updated>2026-10-02T15:36:21.447019+00:00</updated>
    <content>bdu:2023-01835</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-01835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0268</id>
    <title>certfr-2023-avi-0268 — Une vulnérabilité a été découverte dans &lt;span class="textit"&gt;Mozilla
Thunderbird&lt;/span&gt;. Elle permet à un attaquant de…</title>
    <updated>2026-10-02T15:36:21.447038+00:00</updated>
    <content>certfr-2023-avi-0268</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-kh83435</id>
    <title>CLEANSTART-2024-KH83435 — matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript</title>
    <updated>2026-10-02T15:36:21.447054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: element-web</p>
<p>Security vulnerability affects the element-web package. matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-kh83435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-218133</id>
    <title>EUVD-2026-218133</title>
    <updated>2026-10-02T15:36:21.447076+00:00</updated>
    <content>EUVD-2026-218133</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-218133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28427</id>
    <title>fkie_cve-2023-28427</title>
    <updated>2026-10-02T15:36:21.447087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This vulnerability is distinct from GHSA-rfv9-x7hh-xc32 which covers a similar issue. The issue has been patched in matrix-js-sdk 24.0.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-28427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mwq8-fjpf-c2gr</id>
    <title>GHSA-mwq8-fjpf-c2gr — Prototype pollution in matrix-js-sdk (part 2)</title>
    <updated>2026-10-02T15:36:21.447113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: matrix-js-sdk</p>
<p>### Impact</p>
<p>In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-js-sdk functionality, causing denial of service and potentially affecting program logic.</p>
<p>(This is part 2, where [CVE-2022-36059](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36059) / [GHSA-rfv9-x7hh-xc32](https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-rfv9-x7hh-xc32) is part 1. Part 2 covers remaining vectors not covered by part 1, found in a codebase audit scheduled after part 1.)</p>
<p>### Patches
The issue has been patched in matrix-js-sdk 24.0.0.</p>
<p>### Workarounds
None.</p>
<p>### References</p>
<p>- [Release blog post](https://matrix.org/blog/2023/03/28/security-releases-matrix-js-sdk-24-0-0-and-matrix-react-sdk-3-69-0)
- The advisory [GHSA-rfv9-x7hh-xc32](https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-rfv9-x7hh-xc32) ([CVE-2022-36059](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36059)) refers to an initial set of vulnerable locations discovered and patched in matrix-js-sdk 19.4.0. We opted not to disclose that advisory while we performed an audit of the codebase and are now disclosing it jointly with this one.</p>
<p>### For more information
If you have any questions or comments about this advisory please email us at [security at matrix.org](mailto:security@matrix.org).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mwq8-fjpf-c2gr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-28427</id>
    <title>gsd-2023-28427</title>
    <updated>2026-10-02T15:36:21.447147+00:00</updated>
    <content>gsd-2023-28427</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-28427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12823-1</id>
    <title>openSUSE-SU-2024:12823-1 — element-web-1.11.26-1.1 on GA media</title>
    <updated>2026-10-02T15:36:21.447159+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>element-web-1.11.26-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12823-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:1803</id>
    <title>RHSA-2023:1803 — Red Hat Security Advisory: thunderbird security update</title>
    <updated>2026-10-02T15:36:21.447176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Thunderbird: Revocation status of S/Mime recipient certificates was not checked Mozilla: Memory Corruption in Safe Browsing Code Mozilla: libwebp: Double-free in libwebp Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack Thunderbird: Hang when processing certain OpenPGP messages Mozilla: Fullscreen notification obscured Mozilla: Potential Memory Corruption following Garbage Collector compaction Mozilla: Invalid free from JavaScript code Mozilla: Content-Disposition filename truncation leads to Reflected File Download Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux Mozilla: Incorrect optimization result on ARM64 Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:1803"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28427</id>
    <title>UBUNTU-CVE-2023-28427</title>
    <updated>2026-10-02T15:36:21.447211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-matrix-js-sdk, Ubuntu:22.04:LTS: node-matrix-js-sdk, Ubuntu:24.04:LTS: node-matrix-js-sdk</p>
<p>matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This vulnerability is distinct from GHSA-rfv9-x7hh-xc32 which covers a similar issue. The issue has been patched in matrix-js-sdk 24.0.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0789</id>
    <title>WID-SEC-W-2023-0789 — Mozilla Thunderbird: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T15:36:21.447261+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Mozilla Thunderbird ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0789"/>
  </entry>
</feed>
