<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T06:38:12.435512+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:10195</id>
    <title>ALSA-2025:10195 — Important: thunderbird security update</title>
    <updated>2026-10-05T06:38:12.686012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: thunderbird</p>
<p>Mozilla Thunderbird is a standalone mail and newsgroup client.</p>
<p>Security Fix(es):</p>
<p>* thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (CVE-2025-5986)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:10195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08579</id>
    <title>bdu:2025-08579</title>
    <updated>2026-10-05T06:38:12.686107+00:00</updated>
    <content>bdu:2025-08579</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0491</id>
    <title>certfr-2025-avi-0491 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-05T06:38:12.686132+00:00</updated>
    <content>certfr-2025-avi-0491</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0491"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290731</id>
    <title>EUVD-2026-290731</title>
    <updated>2026-10-05T06:38:12.686165+00:00</updated>
    <content>EUVD-2026-290731</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290731"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-5986</id>
    <title>fkie_cve-2025-5986</title>
    <updated>2026-10-05T06:38:12.686188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability was fixed in Thunderbird 128.11.1 and Thunderbird 139.0.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-5986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q7fj-77gc-45xq</id>
    <title>GHSA-q7fj-77gc-45xq</title>
    <updated>2026-10-05T06:38:12.686232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird &lt; 128.11.1 and Thunderbird &lt; 139.0.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q7fj-77gc-45xq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1835</id>
    <title>OESA-2025-1835 — thunderbird security update</title>
    <updated>2026-10-05T06:38:12.686265+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: thunderbird</p>
<p>Mozilla Thunderbird is a standalone mail and newsgroup client.

Security Fix(es):</p>
<p>A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Firefox ESR &amp;lt; 115.17, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.(CVE-2024-10458)</p>
<p>An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Firefox ESR &amp;lt; 115.17, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.(CVE-2024-10459)</p>
<p>The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.(CVE-2024-10460)</p>
<p>In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.(CVE-2024-10461)</p>
<p>Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.(CVE-2024-10462)</p>
<p>Video frames could have been leaked between origins in some situations. Thi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15204-1</id>
    <title>openSUSE-SU-2025:15204-1 — MozillaThunderbird-128.11.1-2.1 on GA media</title>
    <updated>2026-10-05T06:38:12.686655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MozillaThunderbird-128.11.1-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15204-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:10159</id>
    <title>RHSA-2025:10159 — Red Hat Security Advisory: thunderbird security update</title>
    <updated>2026-10-05T06:38:12.686693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links firefox: thunderbird: Use-after-free in FontFaceSet firefox: thunderbird: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID firefox: thunderbird: Incorrect parsing of URLs could have allowed embedding of youtube.com firefox: thunderbird: Content-Disposition header ignored when a file is included in an embed or object tag</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:10159"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5986</id>
    <title>UBUNTU-CVE-2025-5986</title>
    <updated>2026-10-05T06:38:12.686748+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: thunderbird</p>
<p>A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability was fixed in Thunderbird 128.11.1 and Thunderbird 139.0.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1301</id>
    <title>WID-SEC-W-2025-1301 — Mozilla Thunderbird: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen</title>
    <updated>2026-10-05T06:38:12.686801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann eine Schwachstelle in Mozilla Thunderbird ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1301"/>
  </entry>
</feed>
