<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:43:38.858661+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:1493</id>
    <title>ALSA-2024:1493 — Moderate: thunderbird security update</title>
    <updated>2026-10-02T18:43:39.088246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: thunderbird</p>
<p>Mozilla Thunderbird is a standalone mail and newsgroup client.</p>
<p>This update upgrades Thunderbird to version 115.9.0.</p>
<p>Security Fix(es):</p>
<p>* nss: timing attack against RSA decryption (CVE-2023-5388)
* Mozilla: Crash in NSS TLS method (CVE-2024-0743)
* Mozilla: Leaking of encrypted email subjects to other conversations  (CVE-2024-1936)
* Mozilla: JIT code failed to save return registers on Armv7-A (CVE-2024-2607)
* Mozilla: Integer overflow could have led to out of bounds write
(CVE-2024-2608)
* Mozilla: Improper handling of html and body tags enabled CSP nonce leakage
(CVE-2024-2610)
* Mozilla: Clickjacking vulnerability could have led to a user accidentally
granting permissions (CVE-2024-2611)
* Mozilla: Self referencing object could have potentially led to a
use-after-free (CVE-2024-2612)
* Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and
Thunderbird 115.9 (CVE-2024-2614)</p>
<p>For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:1493"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02159</id>
    <title>bdu:2024-02159</title>
    <updated>2026-10-02T18:43:39.088322+00:00</updated>
    <content>bdu:2024-02159</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02159"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0183</id>
    <title>certfr-2024-avi-0183 — Une vulnérabilité a été découverte dans &lt;span class="textit"&gt;les
produits Mozilla&lt;/span&gt;. Elle permet à un attaquant de…</title>
    <updated>2026-10-02T18:43:39.088341+00:00</updated>
    <content>certfr-2024-avi-0183</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-25572</id>
    <title>cnvd-2024-25572</title>
    <updated>2026-10-02T18:43:39.088357+00:00</updated>
    <content>cnvd-2024-25572</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-25572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-204268</id>
    <title>EUVD-2026-204268</title>
    <updated>2026-10-02T18:43:39.088368+00:00</updated>
    <content>EUVD-2026-204268</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-204268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-1936</id>
    <title>fkie_cve-2024-1936</title>
    <updated>2026-10-02T18:43:39.088378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird &lt; 115.8.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-1936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8v87-67f4-56h2</id>
    <title>GHSA-8v87-67f4-56h2</title>
    <updated>2026-10-02T18:43:39.088404+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird &lt; 115.8.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8v87-67f4-56h2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-1936</id>
    <title>gsd-2024-1936</title>
    <updated>2026-10-02T18:43:39.088422+00:00</updated>
    <content>gsd-2024-1936</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-1936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13753-1</id>
    <title>openSUSE-SU-2024:13753-1 — MozillaThunderbird-115.8.1-1.1 on GA media</title>
    <updated>2026-10-02T18:43:39.088432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MozillaThunderbird-115.8.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13753-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1492</id>
    <title>RHSA-2024:1492 — Red Hat Security Advisory: thunderbird security update</title>
    <updated>2026-10-02T18:43:39.088449+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nss: timing attack against RSA decryption Mozilla: Crash in NSS TLS method Mozilla: Leaking of encrypted email subjects to other conversations Mozilla: JIT code failed to save return registers on Armv7-A Mozilla: Integer overflow could have led to out of bounds write Mozilla: Improper handling of html and body tags enabled CSP nonce leakage Mozilla: Clickjacking vulnerability could have led to a user accidentally granting permissions Mozilla: Self referencing object could have potentially led to a use-after-free Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9 Mozilla: Improve handling of out-of-memory conditions in ICU</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1492"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:0893-1</id>
    <title>SUSE-SU-2024:0893-1 — Security update for MozillaThunderbird</title>
    <updated>2026-10-02T18:43:39.088523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaThunderbird</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:0893-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-1936</id>
    <title>UBUNTU-CVE-2024-1936</title>
    <updated>2026-10-02T18:43:39.088558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: thunderbird</p>
<p>The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird &lt; 115.8.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-1936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0545</id>
    <title>WID-SEC-W-2024-0545 — Mozilla Thunderbird: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-02T18:43:39.088610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Mozilla Thunderbird ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0545"/>
  </entry>
</feed>
