<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:56:27.695797+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:58897</id>
    <title>ALSA-2026:58897 — Important: firefox security update</title>
    <updated>2026-10-02T23:56:28.704205+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>Security Fix(es):</p>
<p>* firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983)
  * firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934)
  * firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953)
  * firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987)
  * firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948)
  * firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943)
  * firefox: thunderbird: Information disclosure in the DOM: UI Events &amp; Focus Handling component (CVE-2026-74971)
  * firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941)
  * firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965)
  * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946)
  * firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973)
  * firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949)
  * firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:58897"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1054</id>
    <title>certfr-2026-avi-1054 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T23:56:28.704320+00:00</updated>
    <content>certfr-2026-avi-1054</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1054"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355154</id>
    <title>EUVD-2026-355154</title>
    <updated>2026-10-02T23:56:28.704342+00:00</updated>
    <content>EUVD-2026-355154</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-74973</id>
    <title>fkie_cve-2026-74973</title>
    <updated>2026-10-02T23:56:28.704355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-74973"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cw58-8m9v-83jv</id>
    <title>GHSA-cw58-8m9v-83jv</title>
    <updated>2026-10-02T23:56:28.704378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cw58-8m9v-83jv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3556</id>
    <title>OESA-2026-3556 — firefox security update</title>
    <updated>2026-10-02T23:56:28.704393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo

Security Fix(es):</p>
<p>Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.(CVE-2026-74934)</p>
<p>A privilege escalation vulnerability exists in Mozilla Firefox and Thunderbird in the DOM: Networking component. The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. An attacker could exploit this vulnerability to affect confidentiality, integrity, and availability. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.(CVE-2026-74935)</p>
<p>Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11546-1</id>
    <title>openSUSE-SU-2026:11546-1 — firefox-esr-153.1.0-1.1 on GA media</title>
    <updated>2026-10-02T23:56:28.704450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>firefox-esr-153.1.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11546-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:64813</id>
    <title>RHSA-2026:64813 — Red Hat Security Advisory: firefox security update</title>
    <updated>2026-10-02T23:56:28.704496+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component firefox: thunderbird: Privilege escalation in the DOM: Networking component firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component firefox: thunderbird: Privilege escalation in the DOM: Navigation component firefox: thunderbird: Use-after-free in the Graphics: Text component firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component firefox: Privilege escalation in the Remote Settings Client component firefox: thunderbird: Use-after-free in the Graphics: ImageLib component firefox: thunderbird: Use-after-free in the DOM: Core &amp; HTML component firefox: thunderbird: Information disclosure in the Graphics: Text component firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component firefox: thunderbird: Information disclosure in the Graphics component firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component firefox: thunderbird: Privilege escalation in the Networking: Cookies component firefox: thunderbird: Mitigation bypass in the Safe Browsing component firefox: thunderbird: Mitigation bypass in the Storage: Cache API component firefox: thunderbird: Site isolation issue in the WebExtensions component firefox: Site isolation issue in the Networking: Cookies component firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component f…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:64813"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:58897</id>
    <title>RLSA-2026:58897 — Important: firefox security update</title>
    <updated>2026-10-02T23:56:28.704563+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>Security Fix(es):</p>
<p>* firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983)</p>
<p>* firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934)</p>
<p>* firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953)</p>
<p>* firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987)</p>
<p>* firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948)</p>
<p>* firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943)</p>
<p>* firefox: thunderbird: Information disclosure in the DOM: UI Events &amp; Focus Handling component (CVE-2026-74971)</p>
<p>* firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941)</p>
<p>* firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965)</p>
<p>* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946)</p>
<p>* firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973)</p>
<p>* firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949)</p>
<p>* firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 15…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:58897"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23304-1</id>
    <title>SUSE-SU-2026:23304-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-02T23:56:28.704610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23304-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74973</id>
    <title>UBUNTU-CVE-2026-74973</title>
    <updated>2026-10-02T23:56:28.704645+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115</p>
<p>Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74973"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2911</id>
    <title>WID-SEC-W-2026-2911 — Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:56:28.704678+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Firefox ESR und Thunderbird ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Spoofing- oder Clickjacking-Angriffe durchzuführen oder Denial-of-Service-Zustände herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2911"/>
  </entry>
</feed>
