<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:41:02.089772+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:2883</id>
    <title>ALSA-2024:2883 — Important: firefox security update</title>
    <updated>2026-10-03T01:41:02.523644+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>This update upgrades Firefox to version 115.11.0 ESR.</p>
<p>Security Fix(es):</p>
<p>* firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)
* firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767)
* firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768)
* firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769)
* firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770)
* firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:2883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-06889</id>
    <title>bdu:2024-06889</title>
    <updated>2026-10-03T01:41:02.523731+00:00</updated>
    <content>bdu:2024-06889</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-06889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0396</id>
    <title>certfr-2024-avi-0396 — De multiples vulnérabilités ont été découvertes dans les produits
Mozilla. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-03T01:41:02.523750+00:00</updated>
    <content>certfr-2024-avi-0396</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0396"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-23344</id>
    <title>cnvd-2024-23344</title>
    <updated>2026-10-03T01:41:02.523766+00:00</updated>
    <content>cnvd-2024-23344</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-23344"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-226124</id>
    <title>EUVD-2026-226124</title>
    <updated>2026-10-03T01:41:02.523777+00:00</updated>
    <content>EUVD-2026-226124</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-226124"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-4767</id>
    <title>fkie_cve-2024-4767</title>
    <updated>2026-10-03T01:41:02.523787+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-4767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fffc-4hjp-2r9v</id>
    <title>GHSA-fffc-4hjp-2r9v</title>
    <updated>2026-10-03T01:41:02.523809+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fffc-4hjp-2r9v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1786</id>
    <title>OESA-2024-1786 — firefox security update</title>
    <updated>2026-10-03T01:41:02.523825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: firefox</p>
<p>Mozilla Firefox is a standalone web browser, designed for standards compliance and performance.  Its functionality can be enhanced via a plethora of extensions.

Security Fix(es):

There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox &amp;lt; 125, Firefox ESR &amp;lt; 115.10, and Thunderbird &amp;lt; 115.10.(CVE-2024-3302)

GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox &amp;lt; 125, Firefox ESR &amp;lt; 115.10, and Thunderbird &amp;lt; 115.10.(CVE-2024-3852)

In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox &amp;lt; 125, Firefox ESR &amp;lt; 115.10, and Thunderbird &amp;lt; 115.10.(CVE-2024-3854)

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox &amp;lt; 125, Firefox ESR &amp;lt; 115.10, and Thunderbird &amp;lt; 115.10.(CVE-2024-3859)

If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox &amp;lt; 125, Firefox ESR &amp;lt; 115.10, and Thunderbird &amp;lt; 115.10.(CVE-2024-3861)

If the `browser.privatebrowsing.autostart` preference is enabled…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1786"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13980-1</id>
    <title>openSUSE-SU-2024:13980-1 — MozillaFirefox-126.0-1.1 on GA media</title>
    <updated>2026-10-03T01:41:02.523862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MozillaFirefox-126.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13980-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:2882</id>
    <title>RHSA-2024:2882 — Red Hat Security Advisory: firefox security update</title>
    <updated>2026-10-03T01:41:02.523888+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mozilla: Arbitrary JavaScript execution in PDF.js Mozilla: IndexedDB files retained in private browsing mode Mozilla: Potential permissions request bypass via clickjacking Mozilla: Cross-origin responses could be distinguished between script and non-script content-types Mozilla: Use-after-free could occur when printing to PDF Mozilla: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:2882"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1676-1</id>
    <title>SUSE-SU-2024:1676-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-03T01:41:02.523913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1676-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4767</id>
    <title>UBUNTU-CVE-2024-4767</title>
    <updated>2026-10-03T01:41:02.523934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: thunderbird, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird and 1 more</p>
<p>If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1151</id>
    <title>WID-SEC-W-2024-1151 — Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
    <updated>2026-10-03T01:41:02.523967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting (XSS)-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1151"/>
  </entry>
</feed>
