<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:07:02.500921+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:70642</id>
    <title>ALSA-2026:70642 — Important: thunderbird security update</title>
    <updated>2026-10-03T09:07:02.601120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: thunderbird</p>
<p>Mozilla Thunderbird is a standalone mail and newsgroup client.</p>
<p>Security Fix(es):</p>
<p>* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)
  * firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)
  * firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)
  * firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)
  * firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)
  * firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)
  * firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)
  * firefox: Use-after-free in the DOM: Core &amp; HTML component (CVE-2026-84124)
  * firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)
  * firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)
  * thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)
  * thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)
  * thunderbird: One byte overflow read in mail parser (CVE-2026-84640)
  * firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)
  * firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)
  * firefox: thunderbird: U…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:70642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1183</id>
    <title>certfr-2026-avi-1183 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-03T09:07:02.601212+00:00</updated>
    <content>certfr-2026-avi-1183</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-373827</id>
    <title>EUVD-2026-373827</title>
    <updated>2026-10-03T09:07:02.601234+00:00</updated>
    <content>EUVD-2026-373827</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-373827"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92238</id>
    <title>fkie_cve-2026-92238</title>
    <updated>2026-10-03T09:07:02.601247+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-92238"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w2rw-r9p8-wp72</id>
    <title>GHSA-w2rw-r9p8-wp72</title>
    <updated>2026-10-03T09:07:02.601268+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w2rw-r9p8-wp72"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11827-1</id>
    <title>openSUSE-SU-2026:11827-1 — MozillaThunderbird-140.16.0-1.1 on GA media</title>
    <updated>2026-10-03T09:07:02.601283+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MozillaThunderbird-140.16.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11827-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:70642</id>
    <title>RLSA-2026:70642 — Important: thunderbird security update</title>
    <updated>2026-10-03T09:07:02.601316+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: thunderbird</p>
<p>Mozilla Thunderbird is a standalone mail and newsgroup client.</p>
<p>Security Fix(es):</p>
<p>* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)</p>
<p>* firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)</p>
<p>* firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)</p>
<p>* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)</p>
<p>* firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)</p>
<p>* firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)</p>
<p>* firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)</p>
<p>* firefox: Use-after-free in the DOM: Core &amp; HTML component (CVE-2026-84124)</p>
<p>* firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)</p>
<p>* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)</p>
<p>* thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)</p>
<p>* thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)</p>
<p>* thunderbird: One byte overflow read in mail parser (CVE-2026-84640)</p>
<p>* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)</p>
<p>* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)</p>
<p>* firefox: thunderbird: Use-after-free in the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:70642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-92238</id>
    <title>UBUNTU-CVE-2026-92238</title>
    <updated>2026-10-03T09:07:02.601368+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115</p>
<p>A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-92238"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3375</id>
    <title>WID-SEC-W-2026-3375 — Mozilla Firefox und Thunderbird: Mehrere Schwachstellen</title>
    <updated>2026-10-03T09:07:02.601401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Firefox ESR und Thunderbird ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren, den Speicher zu beschädigen, Denial-of-Service-Zustände zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3375"/>
  </entry>
</feed>
