<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:35:26.320583+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:8196</id>
    <title>ALSA-2025:8196 — Important: thunderbird security update</title>
    <updated>2026-10-03T13:35:26.586144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: thunderbird</p>
<p>Mozilla Thunderbird is a standalone mail and newsgroup client.</p>
<p>Security Fix(es):</p>
<p>* thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link (CVE-2025-3909)
  * thunderbird: Sender Spoofing via Malformed From Header in Thunderbird (CVE-2025-3875)
  * thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (CVE-2025-3877)
  * thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking (CVE-2025-3932)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:8196"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-05735</id>
    <title>bdu:2025-05735</title>
    <updated>2026-10-03T13:35:26.586207+00:00</updated>
    <content>bdu:2025-05735</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-05735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0411</id>
    <title>certfr-2025-avi-0411 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-03T13:35:26.586225+00:00</updated>
    <content>certfr-2025-avi-0411</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-3877</id>
    <title>fkie_cve-2025-3877</title>
    <updated>2026-10-03T13:35:26.586241+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rejected reason: This CVE was marked as fixed, but due to other code landing - was not actually fixed.  It was subsequently fixed in CVE-2025-5986.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-3877"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-69m9-2g5j-9m4h</id>
    <title>GHSA-69m9-2g5j-9m4h</title>
    <updated>2026-10-03T13:35:26.586262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird &lt; 128.10.1 and Thunderbird &lt; 138.0.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-69m9-2g5j-9m4h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15131-1</id>
    <title>openSUSE-SU-2025:15131-1 — MozillaThunderbird-128.10.1-1.1 on GA media</title>
    <updated>2026-10-03T13:35:26.586282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MozillaThunderbird-128.10.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15131-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:8196</id>
    <title>RHSA-2025:8196 — Red Hat Security Advisory: thunderbird security update</title>
    <updated>2026-10-03T13:35:26.586302+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>thunderbird: Sender Spoofing via Malformed From Header in Thunderbird thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:8196"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01660-1</id>
    <title>SUSE-SU-2025:01660-1 — Security update for MozillaThunderbird</title>
    <updated>2026-10-03T13:35:26.586323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaThunderbird</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01660-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3877</id>
    <title>Withdrawn: UBUNTU-CVE-2025-3877</title>
    <updated>2026-10-03T13:35:26.586339+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.10: thunderbird, Ubuntu:24.04:LTS: thunderbird, Ubuntu:25.04: thunderbird</p>
<p>Rejected reason: This CVE was marked as fixed, but due to other code landing - was not actually fixed.  It was subsequently fixed in CVE-2025-5986.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3877"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1062</id>
    <title>WID-SEC-W-2025-1062 — Mozilla Thunderbird: Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:35:26.586362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Thunderbird ausnutzenum beliebigen Programmcode auszuführen, vertrauliche Informationen preiszugeben, einen Denial-of-Service-Zustand herbeizuführen oder Absender-Spoofing durchzuführen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1062"/>
  </entry>
</feed>
