<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:54:19 +0000</lastBuildDate>
    <item>
      <title>certfr-2021-avi-796 — De multiples vulnérabilités ont été découvertes dans Mozilla
Thunderbird. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-796</link>
      <description>certfr-2021-avi-796</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-796</guid>
    </item>
    <item>
      <title>cnvd-2022-36982</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-36982</link>
      <description>cnvd-2022-36982</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-36982</guid>
    </item>
    <item>
      <title>EUVD-2026-30280</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-30280</link>
      <description>EUVD-2026-30280</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-30280</guid>
    </item>
    <item>
      <title>fkie_cve-2021-38502</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-38502</link>
      <description>&lt;p&gt;Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird &amp;lt; 91.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird &amp;lt; 91.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-38502</guid>
    </item>
    <item>
      <title>GHSA-wf24-4m95-7wjm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wf24-4m95-7wjm</link>
      <description>&lt;p&gt;Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird &amp;lt; 91.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird &amp;lt; 91.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wf24-4m95-7wjm</guid>
    </item>
    <item>
      <title>gsd-2021-38502</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-38502</link>
      <description>gsd-2021-38502</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-38502</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1635-1 — Security update for MozillaThunderbird</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1635-1</link>
      <description>&lt;p&gt;Security update for MozillaThunderbird&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaThunderbird&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1635-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3839 — Red Hat Security Advisory: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3839</link>
      <description>&lt;p&gt;rust-crossbeam-deque: race condition may lead to double free Mozilla: Use-after-free in MessageTask Mozilla: Validation message could have been overlaid on another origin Mozilla: Use-after-free of nsLanguageAtomService object Mozilla: Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and Firefox ESR 91.2 Mozilla: Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2 Mozilla: Downgrade attack on SMTP STARTTLS connections&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rust-crossbeam-deque: race condition may lead to double free Mozilla: Use-after-free in MessageTask Mozilla: Validation message could have been overlaid on another origin Mozilla: Use-after-free of nsLanguageAtomService object Mozilla: Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and Firefox ESR 91.2 Mozilla: Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2 Mozilla: Downgrade attack on SMTP STARTTLS connections&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3839</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:4150-1 — Security update for MozillaThunderbird</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:4150-1</link>
      <description>&lt;p&gt;Security update for MozillaThunderbird&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaThunderbird&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:4150-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-38502</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38502</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: thunderbird, Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird &amp;lt; 91.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: thunderbird, Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird &amp;lt; 91.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38502</guid>
    </item>
  </channel>
</rss>
