<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T02:08:08.426054+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:21280</id>
    <title>ALSA-2025:21280 — Important: firefox security update</title>
    <updated>2026-10-06T02:08:08.469938+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>Security Fix(es):</p>
<p>* firefox: Mitigation bypass in the DOM: Security component (CVE-2025-13018)
  * firefox: Use-after-free in the Audio/Video component (CVE-2025-13014)
  * firefox: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2025-13016)
  * firefox: Same-origin policy bypass in the DOM: Workers component (CVE-2025-13019)
  * firefox: Use-after-free in the WebRTC: Audio/Video component (CVE-2025-13020)
  * firefox: Race condition in the Graphics component (CVE-2025-13012)
  * firefox: Spoofing issue in Firefox (CVE-2025-13015)
  * firefox: Mitigation bypass in the DOM: Core &amp; HTML component (CVE-2025-13013)
  * firefox: Same-origin policy bypass in the DOM: Notifications component (CVE-2025-13017)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:21280"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14551</id>
    <title>bdu:2025-14551</title>
    <updated>2026-10-06T02:08:08.470022+00:00</updated>
    <content>bdu:2025-14551</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14551"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0991</id>
    <title>certfr-2025-avi-0991 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-06T02:08:08.470041+00:00</updated>
    <content>certfr-2025-avi-0991</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0991"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-28718</id>
    <title>cnvd-2025-28718</title>
    <updated>2026-10-06T02:08:08.470058+00:00</updated>
    <content>cnvd-2025-28718</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-28718"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290679</id>
    <title>EUVD-2026-290679</title>
    <updated>2026-10-06T02:08:08.470070+00:00</updated>
    <content>EUVD-2026-290679</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-13012</id>
    <title>fkie_cve-2025-13012</title>
    <updated>2026-10-06T02:08:08.470080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-13012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ghxv-675w-53v8</id>
    <title>GHSA-ghxv-675w-53v8</title>
    <updated>2026-10-06T02:08:08.470102+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Race condition in the Graphics component. This vulnerability affects Firefox &lt; 145, Firefox ESR &lt; 140.5, and Firefox ESR &lt; 115.30.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ghxv-675w-53v8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2701</id>
    <title>OESA-2025-2701 — firefox security update</title>
    <updated>2026-10-06T02:08:08.470117+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo

Security Fix(es):</p>
<p>Race condition in the Graphics component. This vulnerability affects Firefox &amp;lt; 145, Firefox ESR &amp;lt; 140.5, and Firefox ESR &amp;lt; 115.30.(CVE-2025-13012)</p>
<p>Mitigation bypass in the DOM: Core &amp;amp; HTML component. This vulnerability affects Firefox &amp;lt; 145, Firefox ESR &amp;lt; 140.5, Firefox ESR &amp;lt; 115.30, Thunderbird &amp;lt; 145, and Thunderbird &amp;lt; 140.5.(CVE-2025-13013)</p>
<p>Use-after-free in the Audio/Video component. This vulnerability affects Firefox &amp;lt; 145, Firefox ESR &amp;lt; 140.5, and Firefox ESR &amp;lt; 115.30.(CVE-2025-13014)</p>
<p>Spoofing issue in Firefox. This vulnerability affects Firefox &amp;lt; 145, Firefox ESR &amp;lt; 140.5, and Firefox ESR &amp;lt; 115.30.(CVE-2025-13015)</p>
<p>Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox &amp;lt; 145 and Firefox ESR &amp;lt; 140.5.(CVE-2025-13016)</p>
<p>Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15735-1</id>
    <title>openSUSE-SU-2025:15735-1 — MozillaFirefox-145.0-1.1 on GA media</title>
    <updated>2026-10-06T02:08:08.470160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MozillaFirefox-145.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15735-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:21120</id>
    <title>RHSA-2025:21120 — Red Hat Security Advisory: firefox security update</title>
    <updated>2026-10-06T02:08:08.470187+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>firefox: thunderbird: Race condition in the Graphics component firefox: thunderbird: Mitigation bypass in the DOM: Core &amp; HTML component firefox: thunderbird: Use-after-free in the Audio/Video component firefox: thunderbird: Spoofing issue in Firefox firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component firefox: thunderbird: Same-origin policy bypass in the DOM: Notifications component firefox: thunderbird: Mitigation bypass in the DOM: Security component firefox: thunderbird: Same-origin policy bypass in the DOM: Workers component firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:21120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21021-1</id>
    <title>SUSE-SU-2025:21021-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-06T02:08:08.470219+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21021-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-13012</id>
    <title>UBUNTU-CVE-2025-13012</title>
    <updated>2026-10-06T02:08:08.470241+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115</p>
<p>Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-13012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2566</id>
    <title>WID-SEC-W-2025-2566 — Mozilla Firefox und Firefox ESR: Mehrere Schwachstellen</title>
    <updated>2026-10-06T02:08:08.470271+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Firefox ESR ausnutzen, um beliebigen Code auszuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Daten aus anderen Ursprüngen zu lesen oder aus der Sandbox auszubrechen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2566"/>
  </entry>
</feed>
