<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:29:31 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-02934</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-02934</link>
      <description>bdu:2019-02934</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-02934</guid>
    </item>
    <item>
      <title>certfr-2019-avi-316 — De multiples vulnérabilités ont été découvertes dans Mozilla Firefox.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-316</link>
      <description>certfr-2019-avi-316</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-316</guid>
    </item>
    <item>
      <title>cnvd-2019-22856</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-22856</link>
      <description>cnvd-2019-22856</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-22856</guid>
    </item>
    <item>
      <title>EUVD-2026-54556</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-54556</link>
      <description>EUVD-2026-54556</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-54556</guid>
    </item>
    <item>
      <title>fkie_cve-2019-11712</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-11712</link>
      <description>&lt;p&gt;POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-11712</guid>
    </item>
    <item>
      <title>GHSA-f95x-f7xq-cfm6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f95x-f7xq-cfm6</link>
      <description>&lt;p&gt;POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f95x-f7xq-cfm6</guid>
    </item>
    <item>
      <title>gsd-2019-11712</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-11712</link>
      <description>gsd-2019-11712</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-11712</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:1782-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1782-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:1782-1</guid>
    </item>
    <item>
      <title>RHSA-2019:1765 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:1765</link>
      <description>&lt;p&gt;Mozilla: Sandbox escape via installation of malicious language pack Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 Mozilla: Script injection within domain through inner window reuse Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects Mozilla: Use-after-free with HTTP/2 cached stream Mozilla: HTML parsing error can contribute to content XSS Mozilla: Caret character improperly escaped in origins Mozilla: Same-origin policy treats all files in a directory as having the same-origin&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mozilla: Sandbox escape via installation of malicious language pack Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 Mozilla: Script injection within domain through inner window reuse Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects Mozilla: Use-after-free with HTTP/2 cached stream Mozilla: HTML parsing error can contribute to content XSS Mozilla: Caret character improperly escaped in origins Mozilla: Same-origin policy treats all files in a directory as having the same-origin&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:1765</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:14124-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:14124-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:14124-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-11712</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-11712</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: firefox, Ubuntu:16.04:LTS: thunderbird, Ubuntu:18.04:LTS: firefox, Ubuntu:18.04:LTS: thunderbird, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs52&lt;/p&gt;
&lt;p&gt;POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: firefox, Ubuntu:16.04:LTS: thunderbird, Ubuntu:18.04:LTS: firefox, Ubuntu:18.04:LTS: thunderbird, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs52&lt;/p&gt;
&lt;p&gt;POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-11712</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0459 — Mozilla Firefox/Firefox ESR: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0459</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Firefox ESR ausnutzen, um einen Denial of Service Angriff durchzuführen, Daten zu manipulieren, Sicherheitsmechanismen zu umgehen, vertrauliche Daten einzusehen oder Code mit den Privilegien des Angegriffenen zur Ausführung zu bringen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Firefox ESR ausnutzen, um einen Denial of Service Angriff durchzuführen, Daten zu manipulieren, Sicherheitsmechanismen zu umgehen, vertrauliche Daten einzusehen oder Code mit den Privilegien des Angegriffenen zur Ausführung zu bringen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0459</guid>
    </item>
  </channel>
</rss>
