<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:43:51 +0000</lastBuildDate>
    <item>
      <title>certa-2009-avi-048 — Plusieurs vulnérabilités affectent Mozilla Firefox et permettent à une
personne malintentionnée de réaliser un grand no…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2009-avi-048</link>
      <description>certa-2009-avi-048</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2009-avi-048</guid>
    </item>
    <item>
      <title>EUVD-2026-121499</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-121499</link>
      <description>EUVD-2026-121499</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-121499</guid>
    </item>
    <item>
      <title>fkie_cve-2009-0356</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2009-0356</link>
      <description>&lt;p&gt;Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2009-0356</guid>
    </item>
    <item>
      <title>GHSA-95pc-m84q-vvmm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-95pc-m84q-vvmm</link>
      <description>&lt;p&gt;Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-95pc-m84q-vvmm</guid>
    </item>
    <item>
      <title>gsd-2009-0356</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2009-0356</link>
      <description>gsd-2009-0356</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2009-0356</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10600-1 — MozillaFirefox-92.0-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10600-1</link>
      <description>&lt;p&gt;MozillaFirefox-92.0-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaFirefox-92.0-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10600-1</guid>
    </item>
    <item>
      <title>RHSA-2009:0256 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2009:0256</link>
      <description>&lt;p&gt;Firefox layout crashes with evidence of memory corruption Firefox javascript crashes with evidence of memory corruption Firefox XSS using a chrome XBL method and window.eval Firefox local file stealing with SessionStore Firefox Chrome privilege escalation via local .desktop files Firefox XMLHttpRequest allows reading HTTPOnly cookies Firefox directives to not cache pages ignored&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Firefox layout crashes with evidence of memory corruption Firefox javascript crashes with evidence of memory corruption Firefox XSS using a chrome XBL method and window.eval Firefox local file stealing with SessionStore Firefox Chrome privilege escalation via local .desktop files Firefox XMLHttpRequest allows reading HTTPOnly cookies Firefox directives to not cache pages ignored&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2009:0256</guid>
    </item>
  </channel>
</rss>
