<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:41:02 +0000</lastBuildDate>
    <item>
      <title>certfr-2015-avi-020 — De multiples vulnérabilités ont été corrigées dans les produits &lt;span
class="textit"&gt;Mozilla&lt;/span&gt;. Certaines d'entre…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2015-avi-020</link>
      <description>certfr-2015-avi-020</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2015-avi-020</guid>
    </item>
    <item>
      <title>cnvd-2015-00365</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2015-00365</link>
      <description>cnvd-2015-00365</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2015-00365</guid>
    </item>
    <item>
      <title>EUVD-2026-103419</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-103419</link>
      <description>EUVD-2026-103419</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-103419</guid>
    </item>
    <item>
      <title>fkie_cve-2014-8638</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-8638</link>
      <description>&lt;p&gt;The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-8638</guid>
    </item>
    <item>
      <title>GHSA-38xr-6jm2-v69w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-38xr-6jm2-v69w</link>
      <description>&lt;p&gt;The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-38xr-6jm2-v69w</guid>
    </item>
    <item>
      <title>gsd-2014-8638</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-8638</link>
      <description>gsd-2014-8638</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-8638</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10071-1 — MozillaFirefox-50.1.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10071-1</link>
      <description>&lt;p&gt;MozillaFirefox-50.1.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaFirefox-50.1.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10071-1</guid>
    </item>
    <item>
      <title>RHSA-2015:0047 — Red Hat Security Advisory: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2015:0047</link>
      <description>&lt;p&gt;Mozilla: Miscellaneous memory safety hazards (rv:31.4) (MFSA 2015-01) Mozilla: sendBeacon requests lack an Origin header (MFSA 2015-03) Mozilla: Cookie injection through Proxy Authenticate responses (MFSA 2015-04)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mozilla: Miscellaneous memory safety hazards (rv:31.4) (MFSA 2015-01) Mozilla: sendBeacon requests lack an Origin header (MFSA 2015-03) Mozilla: Cookie injection through Proxy Authenticate responses (MFSA 2015-04)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2015:0047</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-8638</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-8638</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: firefox, Ubuntu:14.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: firefox, Ubuntu:14.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-8638</guid>
    </item>
  </channel>
</rss>
