<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:33:02 +0000</lastBuildDate>
    <item>
      <title>certa-2009-avi-157 — Plusieurs vulnérabilités ont été identifiées dans le navigateur Mozilla
Firefox. L'exploitation de celles-ci peut avoir…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2009-avi-157</link>
      <description>certa-2009-avi-157</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2009-avi-157</guid>
    </item>
    <item>
      <title>EUVD-2026-122361</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-122361</link>
      <description>EUVD-2026-122361</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-122361</guid>
    </item>
    <item>
      <title>fkie_cve-2009-1312</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2009-1312</link>
      <description>&lt;p&gt;Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2009-1312</guid>
    </item>
    <item>
      <title>GHSA-3mmx-h8fr-v7j4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3mmx-h8fr-v7j4</link>
      <description>&lt;p&gt;Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3mmx-h8fr-v7j4</guid>
    </item>
    <item>
      <title>gsd-2009-1312</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2009-1312</link>
      <description>gsd-2009-1312</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2009-1312</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10071-1 — MozillaFirefox-50.1.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10071-1</link>
      <description>&lt;p&gt;MozillaFirefox-50.1.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaFirefox-50.1.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10071-1</guid>
    </item>
    <item>
      <title>RHSA-2009:0436 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2009:0436</link>
      <description>&lt;p&gt;firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks) Firefox 3 Layout engine crashes Firefox 2 and 3 Layout engine crash Firefox 3 JavaScript engine crashes Firefox 2 and 3 JavaScript engine crash jar: scheme ignores the content-disposition: header on the inner URI view-source: protocol Firefox XSS hazard using third-party stylesheets and XBL bindings Firefox Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString Firefox Malicious search plugins can inject code into arbitrary sites Firefox POST data sent to wrong site when saving web page with embedded frame javascript: URIs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks) Firefox 3 Layout engine crashes Firefox 2 and 3 Layout engine crash Firefox 3 JavaScript engine crashes Firefox 2 and 3 JavaScript engine crash jar: scheme ignores the content-disposition: header on the inner URI view-source: protocol Firefox XSS hazard using third-party stylesheets and XBL bindings Firefox Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString Firefox Malicious search plugins can inject code into arbitrary sites Firefox POST data sent to wrong site when saving web page with embedded frame javascript: URIs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2009:0436</guid>
    </item>
  </channel>
</rss>
