<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:18:54.009948+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:2883</id>
    <title>ALSA-2024:2883 — Important: firefox security update</title>
    <updated>2026-10-02T23:18:54.742464+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>This update upgrades Firefox to version 115.11.0 ESR.</p>
<p>Security Fix(es):</p>
<p>* firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)
* firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767)
* firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768)
* firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769)
* firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770)
* firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:2883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04733</id>
    <title>bdu:2024-04733</title>
    <updated>2026-10-02T23:18:54.742547+00:00</updated>
    <content>bdu:2024-04733</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0396</id>
    <title>certfr-2024-avi-0396 — De multiples vulnérabilités ont été découvertes dans les produits
Mozilla. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T23:18:54.742566+00:00</updated>
    <content>certfr-2024-avi-0396</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0396"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-23340</id>
    <title>cnvd-2024-23340</title>
    <updated>2026-10-02T23:18:54.742582+00:00</updated>
    <content>cnvd-2024-23340</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-23340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-316920</id>
    <title>EUVD-2026-316920</title>
    <updated>2026-10-02T23:18:54.742595+00:00</updated>
    <content>EUVD-2026-316920</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-316920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-4367</id>
    <title>fkie_cve-2024-4367</title>
    <updated>2026-10-02T23:18:54.742606+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-4367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wgrm-67xf-hhpq</id>
    <title>GHSA-wgrm-67xf-hhpq — PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF</title>
    <updated>2026-10-02T23:18:54.742628+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: pdfjs-dist</p>
<p>### Impact
If pdf.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.</p>
<p>### Patches
The patch removes the use of `eval`:
https://github.com/mozilla/pdf.js/pull/18015</p>
<p>### Workarounds
Set the option `isEvalSupported` to `false`.</p>
<p>### References
https://bugzilla.mozilla.org/show_bug.cgi?id=1893645</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wgrm-67xf-hhpq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-134-04</id>
    <title>ICSA-26-134-04 — Siemens Teamcenter</title>
    <updated>2026-10-02T23:18:54.742653+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11. The affected application does not properly encode or filter user-supplied data. This could allow an attacker to inject malicious code that can be executed by other users when they visit the affected page. The affected application contains hardcoded key which is used for obfuscation stored directly into the application.
This could allow an attacker to obtain these keys and misuse them to gain unauthorized access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-134-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0147</id>
    <title>NCSC-2026-0147 — Kwetsbaarheden verholpen in Siemens-producten</title>
    <updated>2026-10-02T23:18:54.742677+00:00</updated>
    <content>NCSC-2026-0147</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2523</id>
    <title>OESA-2024-2523 — firefox security update</title>
    <updated>2026-10-02T23:18:54.742969+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: firefox</p>
<p>Mozilla Firefox is a standalone web browser, designed for standards compliance and performance.  Its functionality can be enhanced via a plethora of extensions.

Security Fix(es):Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.

Security Fix(es):

An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox &amp;lt; 133, Firefox ESR &amp;lt; 128.5, Thunderbird &amp;lt; 133, and Thunderbird &amp;lt; 128.5.(CVE-2024-11692)

Enhanced Tracking Protection&amp;apos;s Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox &amp;lt; 133, Firefox ESR &amp;lt; 128.5, Firefox ESR &amp;lt; 115.18, Thunderbird &amp;lt; 133, and Thunderbird &amp;lt; 128.5.(CVE-2024-11694)

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox &amp;lt; 133, Firefox ESR &amp;lt; 128.5, Thunderbird &amp;lt; 133, and Thunderbird &amp;lt; 128.5.(CVE-2024-11695)

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13980-1</id>
    <title>openSUSE-SU-2024:13980-1 — MozillaFirefox-126.0-1.1 on GA media</title>
    <updated>2026-10-02T23:18:54.743008+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MozillaFirefox-126.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13980-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oxas-adv-2024-0004</id>
    <title>OXAS-ADV-2024-0004 — OX App Suite Security Advisory OXAS-ADV-2024-0004</title>
    <updated>2026-10-02T23:18:54.743035+00:00</updated>
    <content>OXAS-ADV-2024-0004</content>
    <link href="https://cve.radiocsirt.org/vuln/oxas-adv-2024-0004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:2882</id>
    <title>RHSA-2024:2882 — Red Hat Security Advisory: firefox security update</title>
    <updated>2026-10-02T23:18:54.743049+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mozilla: Arbitrary JavaScript execution in PDF.js Mozilla: IndexedDB files retained in private browsing mode Mozilla: Potential permissions request bypass via clickjacking Mozilla: Cross-origin responses could be distinguished between script and non-script content-types Mozilla: Use-after-free could occur when printing to PDF Mozilla: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:2882"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:42062</id>
    <title>RLSA-2026:42062 — Important: webkit2gtk3 security update</title>
    <updated>2026-10-02T23:18:54.743075+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: webkit2gtk3</p>
<p>WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.</p>
<p>Security Fix(es):</p>
<p>* Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)</p>
<p>* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872)</p>
<p>* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663)</p>
<p>* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676)</p>
<p>* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699)</p>
<p>* webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701)</p>
<p>* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705)</p>
<p>* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707)</p>
<p>* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712)</p>
<p>* webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713)</p>
<p>* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715)</p>
<p>* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716)</p>
<p>* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720)</p>
<p>* webkitgtk: webkitgtk: A malicious websi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:42062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-827383</id>
    <title>SSA-827383 — SSA-827383: Multiple Vulnerabilities in Teamcenter</title>
    <updated>2026-10-02T23:18:54.743118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11. The affected application does not properly encode or filter user-supplied data. This could allow an attacker to inject malicious code that can be executed by other users when they visit the affected page. The affected application contains hardcoded key which is used for obfuscation stored directly into the application.
This could allow an attacker to obtain these keys and misuse them to gain unauthorized access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-827383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1676-1</id>
    <title>SUSE-SU-2024:1676-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-02T23:18:54.743141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1676-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4367</id>
    <title>UBUNTU-CVE-2024-4367</title>
    <updated>2026-10-02T23:18:54.743162+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: thunderbird, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird and 1 more</p>
<p>A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1151</id>
    <title>WID-SEC-W-2024-1151 — Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:18:54.743196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting (XSS)-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1151"/>
  </entry>
</feed>
