<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:58:48.913294+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-06469</id>
    <title>bdu:2024-06469</title>
    <updated>2026-10-02T23:58:48.981256+00:00</updated>
    <content>bdu:2024-06469</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-06469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0656</id>
    <title>certfr-2024-avi-0656 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T23:58:48.981304+00:00</updated>
    <content>certfr-2024-avi-0656</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0656"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-37122</id>
    <title>cnvd-2024-37122</title>
    <updated>2026-10-02T23:58:48.981325+00:00</updated>
    <content>cnvd-2024-37122</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-37122"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-223622</id>
    <title>EUVD-2026-223622</title>
    <updated>2026-10-02T23:58:48.981337+00:00</updated>
    <content>EUVD-2026-223622</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-223622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-7531</id>
    <title>fkie_cve-2024-7531</title>
    <updated>2026-10-02T23:58:48.981348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox &lt; 129, Firefox ESR &lt; 115.14, and Firefox ESR &lt; 128.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-7531"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3jj9-9269-99m2</id>
    <title>GHSA-3jj9-9269-99m2</title>
    <updated>2026-10-02T23:58:48.981380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox &lt; 129, Firefox ESR &lt; 115.14, and Firefox ESR &lt; 128.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3jj9-9269-99m2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1976</id>
    <title>OESA-2024-1976 — firefox security update</title>
    <updated>2026-10-02T23:58:48.981399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: firefox</p>
<p>Mozilla Firefox is a standalone web browser, designed for standards compliance and performance.  Its functionality can be enhanced via a plethora of extensions.

Security Fix(es):

By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user&amp;apos;s system. This vulnerability affects Firefox &amp;lt; 127, Firefox ESR &amp;lt; 115.12, and Thunderbird &amp;lt; 115.12.(CVE-2024-5690)

Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox &amp;lt; 125, Firefox ESR &amp;lt; 115.12, and Thunderbird &amp;lt; 115.12.(CVE-2024-5702)

Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox &amp;lt; 129, Firefox ESR &amp;lt; 115.14, Firefox ESR &amp;lt; 128.1, Thunderbird &amp;lt; 128.1, and Thunderbird &amp;lt; 115.14.(CVE-2024-7519)

Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox &amp;lt; 129, Firefox ESR &amp;lt; 115.14, Firefox ESR &amp;lt; 128.1, Thunderbird &amp;lt; 128.1, and Thunderbird &amp;lt; 115.14.(CVE-2024-7521)

Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox &amp;lt; 129, Firefox ESR &amp;lt; 115.14, Firefox ESR &amp;lt; 128.1, Thunderbird &amp;lt; 128.1, and Thunderbird &amp;lt; 115.14.(CVE-2024-7522)

It w…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14260-1</id>
    <title>openSUSE-SU-2024:14260-1 — MozillaFirefox-129.0-1.1 on GA media</title>
    <updated>2026-10-02T23:58:48.981441+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MozillaFirefox-129.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14260-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:6839</id>
    <title>RHSA-2024:6839 — Red Hat Security Advisory: firefox  update</title>
    <updated>2026-10-02T23:58:48.981467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nss: vulnerable to Minerva side-channel information leak Mozilla: Memory corruption in NSS mozilla: nss: PK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel Sandy Bridge machines mozilla: Type Confusion in Async Generators in Javascript Engine mozilla: Type confusion when looking up a property name in a &amp;quot;with&amp;quot; block mozilla: Internal event interfaces were exposed to web content when browser EventHandler listener callbacks ran mozilla: Firefox did not ask before openings news: links in an external application mozilla: Garbage collection could mis-color cross-compartment objects in OOM conditions mozilla: WASM type confusion involving ArrayTypes mozilla: SelectElements could be shown over another site if popups are allowed mozilla: Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:6839"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2876-1</id>
    <title>SUSE-SU-2024:2876-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-02T23:58:48.981500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2876-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-7531</id>
    <title>UBUNTU-CVE-2024-7531</title>
    <updated>2026-10-02T23:58:48.981527+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115</p>
<p>Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox &lt; 129, Firefox ESR &lt; 115.14, and Firefox ESR &lt; 128.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-7531"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1783</id>
    <title>WID-SEC-W-2024-1783 — Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:58:48.981562+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um einen Spoofing-Angriff durchzuführen, beliebigen Code auszuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1783"/>
  </entry>
</feed>
