<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:17:59.222155+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:11747</id>
    <title>ALSA-2025:11747 — Important: firefox security update</title>
    <updated>2026-10-04T08:17:59.261361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>Security Fix(es):</p>
<p>* firefox: thunderbird: Large branch table could lead to truncated instruction (CVE-2025-8028)
  * firefox: thunderbird: Memory safety bugs (CVE-2025-8035)
  * firefox: thunderbird: Incorrect URL stripping in CSP reports (CVE-2025-8031)
  * firefox: thunderbird: JavaScript engine only wrote partial return value to stack (CVE-2025-8027)
  * firefox: thunderbird: Potential user-assisted code execution in ?Copy as cURL? command (CVE-2025-8030)
  * firefox: Memory safety bugs (CVE-2025-8034)
  * firefox: thunderbird: Incorrect JavaScript state machine for generators (CVE-2025-8033)
  * firefox: thunderbird: XSLT documents could bypass CSP (CVE-2025-8032)
  * firefox: thunderbird: javascript: URLs executed on object and embed tags (CVE-2025-8029)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:11747"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10487</id>
    <title>bdu:2025-10487</title>
    <updated>2026-10-04T08:17:59.261436+00:00</updated>
    <content>bdu:2025-10487</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10487"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0615</id>
    <title>certfr-2025-avi-0615 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-04T08:17:59.261466+00:00</updated>
    <content>certfr-2025-avi-0615</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-20064</id>
    <title>cnvd-2025-20064</title>
    <updated>2026-10-04T08:17:59.261533+00:00</updated>
    <content>cnvd-2025-20064</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-20064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342397</id>
    <title>EUVD-2026-342397</title>
    <updated>2026-10-04T08:17:59.261552+00:00</updated>
    <content>EUVD-2026-342397</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342397"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-8032</id>
    <title>fkie_cve-2025-8032</title>
    <updated>2026-10-04T08:17:59.261571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-8032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hxr8-chw2-2wqc</id>
    <title>GHSA-hxr8-chw2-2wqc</title>
    <updated>2026-10-04T08:17:59.261605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability affects Firefox &lt; 141, Firefox ESR &lt; 128.13, Firefox ESR &lt; 140.1, Thunderbird &lt; 141, Thunderbird &lt; 128.13, and Thunderbird &lt; 140.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hxr8-chw2-2wqc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1933</id>
    <title>OESA-2025-1933 — firefox security update</title>
    <updated>2026-10-04T08:17:59.261633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo

Security Fix(es):</p>
<p>A vulnerability was found in Mozilla Thunderbird up to 140 on 64-bit (Mail Client Software). It has been classified as critical.CWE is classifying the issue as CWE-252. The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.This is going to have an impact on confidentiality, integrity, and availability.Upgrading to version 141 eliminates this vulnerability.(CVE-2025-8027)</p>
<p>A vulnerability was found in Mozilla Firefox up to 140 on ARM64 (Web Browser). It has been declared as critical.The CWE definition for the vulnerability is CWE-119. The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.As an impact it is known to affect confidentiality, integrity, and availability.Upgrading to version 141 eliminates this vulnerability.(CVE-2025-8028)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15371-1</id>
    <title>openSUSE-SU-2025:15371-1 — firefox-esr-140.1.0-1.1 on GA media</title>
    <updated>2026-10-04T08:17:59.261753+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>firefox-esr-140.1.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15371-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:11797</id>
    <title>RHSA-2025:11797 — Red Hat Security Advisory: firefox security update</title>
    <updated>2026-10-04T08:17:59.261784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>firefox: thunderbird: JavaScript engine only wrote partial return value to stack firefox: thunderbird: Large branch table could lead to truncated instruction firefox: thunderbird: javascript: URLs executed on object and embed tags firefox: thunderbird: Potential user-assisted code execution in “Copy as cURL” command firefox: thunderbird: Incorrect URL stripping in CSP reports firefox: thunderbird: XSLT documents could bypass CSP firefox: thunderbird: Incorrect JavaScript state machine for generators firefox: thunderbird: Memory safety bugs firefox: thunderbird: Memory safety bugs</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:11797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02531-1</id>
    <title>SUSE-SU-2025:02531-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-04T08:17:59.261816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02531-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8032</id>
    <title>UBUNTU-CVE-2025-8032</title>
    <updated>2026-10-04T08:17:59.261836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115</p>
<p>XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1623</id>
    <title>WID-SEC-W-2025-1623 — Mozilla Firefox , Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
    <updated>2026-10-04T08:17:59.261866+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen und andere, nicht näher definierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1623"/>
  </entry>
</feed>
