<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:50:56.418598+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:10072</id>
    <title>ALSA-2025:10072 — Important: firefox security update</title>
    <updated>2026-10-02T23:50:57.035853+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>Security Fix(es):</p>
<p>* firefox: Content-Disposition header ignored when a file is included in an embed or object tag (CVE-2025-6430)
  * firefox: Use-after-free in FontFaceSet (CVE-2025-6424)
  * firefox: Incorrect parsing of URLs could have allowed embedding of youtube.com (CVE-2025-6429)
  * firefox: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID (CVE-2025-6425)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:10072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07728</id>
    <title>bdu:2025-07728</title>
    <updated>2026-10-02T23:50:57.035926+00:00</updated>
    <content>bdu:2025-07728</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07728"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0536</id>
    <title>certfr-2025-avi-0536 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T23:50:57.035943+00:00</updated>
    <content>certfr-2025-avi-0536</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-15489</id>
    <title>cnvd-2025-15489</title>
    <updated>2026-10-02T23:50:57.035960+00:00</updated>
    <content>cnvd-2025-15489</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-15489"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290784</id>
    <title>EUVD-2026-290784</title>
    <updated>2026-10-02T23:50:57.035971+00:00</updated>
    <content>EUVD-2026-290784</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-6429</id>
    <title>fkie_cve-2025-6429</title>
    <updated>2026-10-02T23:50:57.035981+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-6429"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8r38-4g4q-hgvw</id>
    <title>GHSA-8r38-4g4q-hgvw</title>
    <updated>2026-10-02T23:50:57.036002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox &lt; 140 and Firefox ESR &lt; 128.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8r38-4g4q-hgvw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1717</id>
    <title>OESA-2025-1717 — firefox security update</title>
    <updated>2026-10-02T23:50:57.036019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo

Security Fix(es):</p>
<p>A vulnerability was found in Mozilla Firefox up to 139 (Web Browser). It has been rated as critical.Using CWE to declare the problem leads to CWE-416. Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.Impacted is confidentiality, integrity, and availability.Upgrading to version 140 eliminates this vulnerability.(CVE-2025-6424)</p>
<p>An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox &amp;lt; 140, Firefox ESR &amp;lt; 115.25, Firefox ESR &amp;lt; 128.12, Thunderbird &amp;lt; 140, and Thunderbird &amp;lt; 128.12.(CVE-2025-6425)</p>
<p>Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15216-1</id>
    <title>openSUSE-SU-2025:15216-1 — firefox-esr-128.12.0-1.1 on GA media</title>
    <updated>2026-10-02T23:50:57.036057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>firefox-esr-128.12.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15216-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:10073</id>
    <title>RHSA-2025:10073 — Red Hat Security Advisory: firefox security update</title>
    <updated>2026-10-02T23:50:57.036077+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>firefox: thunderbird: Use-after-free in FontFaceSet firefox: thunderbird: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID firefox: thunderbird: Incorrect parsing of URLs could have allowed embedding of youtube.com firefox: thunderbird: Content-Disposition header ignored when a file is included in an embed or object tag</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:10073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02123-1</id>
    <title>SUSE-SU-2025:02123-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-02T23:50:57.036097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02123-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6429</id>
    <title>UBUNTU-CVE-2025-6429</title>
    <updated>2026-10-02T23:50:57.036112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115</p>
<p>Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6429"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1395</id>
    <title>WID-SEC-W-2025-1395 — Mozilla Firefox: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:50:57.036141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Firefox ESR ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Angriff auszulösen, Sicherheitsmaßnahmen zu umgehen oder einen Cross-Site-Scripting-Angriff zu starten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1395"/>
  </entry>
</feed>
