<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:30:20.617336+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:27717</id>
    <title>ALSA-2026:27717 — Important: firefox security update</title>
    <updated>2026-10-02T23:30:20.836271+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>Security Fix(es):</p>
<p>* firefox: thunderbird: Sandbox escape in the DOM: Workers component (CVE-2026-12294)
  * firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12313)
  * firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12311)
  * firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12290)
  * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12327)
  * firefox: thunderbird: JIT miscompilation in the DOM: Core &amp; HTML component (CVE-2026-12299)
  * firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12329)
  * firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12312)
  * firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12302)
  * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12328)
  * firefox: thunderbird: Incorrect boundary conditions in the Internationalization component (CVE-2026-12330)
  * firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12314)
  * firefox: thunderbird: Memory s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:27717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0764</id>
    <title>certfr-2026-avi-0764 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T23:30:20.836376+00:00</updated>
    <content>certfr-2026-avi-0764</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-26387</id>
    <title>cnvd-2026-26387</title>
    <updated>2026-10-02T23:30:20.836399+00:00</updated>
    <content>cnvd-2026-26387</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-26387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337835</id>
    <title>EUVD-2026-337835</title>
    <updated>2026-10-02T23:30:20.836412+00:00</updated>
    <content>EUVD-2026-337835</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-12296</id>
    <title>fkie_cve-2026-12296</title>
    <updated>2026-10-02T23:30:20.836423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-12296"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2xx6-2jh9-8wmx</id>
    <title>GHSA-2xx6-2jh9-8wmx</title>
    <updated>2026-10-02T23:30:20.836444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2xx6-2jh9-8wmx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2735</id>
    <title>OESA-2026-2735 — firefox security update</title>
    <updated>2026-10-02T23:30:20.836458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.

Security Fix(es):</p>
<p>Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.(CVE-2026-12289)</p>
<p>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.(CVE-2026-12290)</p>
<p>Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.(CVE-2026-12291)</p>
<p>Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.(CVE-2026-12292)</p>
<p>Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.(CVE-2026-12294)</p>
<p>Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.(CVE-2026-12295)</p>
<p>Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.(CVE-2026-12296)</p>
<p>Sandbox escape due to incorrect boundary…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11052-1</id>
    <title>openSUSE-SU-2026:11052-1 — MozillaFirefox-152.0-1.1 on GA media</title>
    <updated>2026-10-02T23:30:20.836509+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MozillaFirefox-152.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11052-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:36100</id>
    <title>RHSA-2026:36100 — Red Hat Security Advisory: firefox security update</title>
    <updated>2026-10-02T23:30:20.836549+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>firefox: thunderbird: Privilege escalation in the Graphics: WebRender component firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 firefox: thunderbird: Use-after-free in the Networking: HTTP component firefox: thunderbird: Incorrect boundary conditions in the Web Audio component firefox: thunderbird: Sandbox escape in the DOM: Workers component firefox: thunderbird: Sandbox escape in the DOM: Navigation component firefox: thunderbird: Sandbox escape in the Security: Process Sandboxing component firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Networking component firefox: thunderbird: Memory safety bug fixed in Firefox ESR 140.12 firefox: thunderbird: JIT miscompilation in the DOM: Core &amp; HTML component firefox: thunderbird: Mitigation bypass in the DOM: Security component firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component firefox: thunderbird: Memory safety b…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:36100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:27717</id>
    <title>RLSA-2026:27717 — Important: firefox security update</title>
    <updated>2026-10-02T23:30:20.836613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>Security Fix(es):</p>
<p>* firefox: thunderbird: Sandbox escape in the DOM: Workers component (CVE-2026-12294)</p>
<p>* firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12313)</p>
<p>* firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12311)</p>
<p>* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12290)</p>
<p>* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12327)</p>
<p>* firefox: thunderbird: JIT miscompilation in the DOM: Core &amp; HTML component (CVE-2026-12299)</p>
<p>* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12329)</p>
<p>* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12312)</p>
<p>* firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12302)</p>
<p>* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12328)</p>
<p>* firefox: thunderbird: Incorrect boundary conditions in the Internationalization component (CVE-2026-12330)</p>
<p>* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12314)</p>
<p>* firefox: thunderbird: Memory safety bug fixed in…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:27717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22351-1</id>
    <title>SUSE-SU-2026:22351-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-02T23:30:20.836657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22351-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12296</id>
    <title>UBUNTU-CVE-2026-12296</title>
    <updated>2026-10-02T23:30:20.836686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115</p>
<p>Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12296"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1959</id>
    <title>WID-SEC-W-2026-1959 — Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:30:20.836717+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Speicherbeschädigungen zu verursachen, Sicherheitsmaßnahmen zu umgehen und aus der Sandbox auszubrechen, vertrauliche Informationen offenzulegen, Daten zu manipulieren und Denial-of-Service-Zustände auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1959"/>
  </entry>
</feed>
