<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:54:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-00723</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-00723</link>
      <description>bdu:2020-00723</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-00723</guid>
    </item>
    <item>
      <title>certfr-2019-avi-316 — De multiples vulnérabilités ont été découvertes dans Mozilla Firefox.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-316</link>
      <description>certfr-2019-avi-316</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-316</guid>
    </item>
    <item>
      <title>cnvd-2019-22851</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-22851</link>
      <description>cnvd-2019-22851</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-22851</guid>
    </item>
    <item>
      <title>EUVD-2026-54594</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-54594</link>
      <description>EUVD-2026-54594</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-54594</guid>
    </item>
    <item>
      <title>fkie_cve-2019-11730</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-11730</link>
      <description>&lt;p&gt;A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app&amp;#39;s predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app&amp;#39;s predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-11730</guid>
    </item>
    <item>
      <title>GHSA-353x-8rf5-m26c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-353x-8rf5-m26c</link>
      <description>&lt;p&gt;A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app&amp;#39;s predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app&amp;#39;s predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-353x-8rf5-m26c</guid>
    </item>
    <item>
      <title>gsd-2019-11730</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-11730</link>
      <description>gsd-2019-11730</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-11730</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:1782-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1782-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:1782-1</guid>
    </item>
    <item>
      <title>RHSA-2019:1765 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:1765</link>
      <description>&lt;p&gt;Mozilla: Sandbox escape via installation of malicious language pack Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 Mozilla: Script injection within domain through inner window reuse Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects Mozilla: Use-after-free with HTTP/2 cached stream Mozilla: HTML parsing error can contribute to content XSS Mozilla: Caret character improperly escaped in origins Mozilla: Same-origin policy treats all files in a directory as having the same-origin&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mozilla: Sandbox escape via installation of malicious language pack Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 Mozilla: Script injection within domain through inner window reuse Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects Mozilla: Use-after-free with HTTP/2 cached stream Mozilla: HTML parsing error can contribute to content XSS Mozilla: Caret character improperly escaped in origins Mozilla: Same-origin policy treats all files in a directory as having the same-origin&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:1765</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:14124-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:14124-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:14124-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-11730</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-11730</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: firefox, Ubuntu:16.04:LTS: thunderbird, Ubuntu:18.04:LTS: firefox, Ubuntu:18.04:LTS: thunderbird, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs52&lt;/p&gt;
&lt;p&gt;A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app&amp;#39;s predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: firefox, Ubuntu:16.04:LTS: thunderbird, Ubuntu:18.04:LTS: firefox, Ubuntu:18.04:LTS: thunderbird, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs52&lt;/p&gt;
&lt;p&gt;A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app&amp;#39;s predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-11730</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0459 — Mozilla Firefox/Firefox ESR: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0459</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Firefox ESR ausnutzen, um einen Denial of Service Angriff durchzuführen, Daten zu manipulieren, Sicherheitsmechanismen zu umgehen, vertrauliche Daten einzusehen oder Code mit den Privilegien des Angegriffenen zur Ausführung zu bringen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Firefox ESR ausnutzen, um einen Denial of Service Angriff durchzuführen, Daten zu manipulieren, Sicherheitsmechanismen zu umgehen, vertrauliche Daten einzusehen oder Code mit den Privilegien des Angegriffenen zur Ausführung zu bringen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0459</guid>
    </item>
  </channel>
</rss>
