<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:59:32 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:5482 — Important: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:5482</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 91.11.
Security Fix(es):
* Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI (CVE-2022-34468)
* Mozilla: Use-after-free in nsSHistory (CVE-2022-34470)
* Mozilla: A popup window could be resized in a way to overlay the address bar with web content (CVE-2022-34479)
* Mozilla: Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11 (CVE-2022-34484)
* Mozilla: Undesired attributes could be set as part of prototype pollution (CVE-2022-2200)
* Mozilla: An email with a mismatching OpenPGP signature date was accepted as valid (CVE-2022-2226)
* Mozilla: CSP bypass enabling stylesheet injection (CVE-2022-31744)
* Mozilla: Unavailable PAC file resulted in OCSP requests being blocked (CVE-2022-34472)
* Mozilla: Potential integer overflow in ReplaceElementsAt (CVE-2022-34481)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 91.11.
Security Fix(es):
* Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI (CVE-2022-34468)
* Mozilla: Use-after-free in nsSHistory (CVE-2022-34470)
* Mozilla: A popup window could be resized in a way to overlay the address bar with web content (CVE-2022-34479)
* Mozilla: Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11 (CVE-2022-34484)
* Mozilla: Undesired attributes could be set as part of prototype pollution (CVE-2022-2200)
* Mozilla: An email with a mismatching OpenPGP signature date was accepted as valid (CVE-2022-2226)
* Mozilla: CSP bypass enabling stylesheet injection (CVE-2022-31744)
* Mozilla: Unavailable PAC file resulted in OCSP requests being blocked (CVE-2022-34472)
* Mozilla: Potential integer overflow in ReplaceElementsAt (CVE-2022-34481)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:5482</guid>
    </item>
    <item>
      <title>bdu:2022-04077</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04077</link>
      <description>bdu:2022-04077</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04077</guid>
    </item>
    <item>
      <title>certfr-2022-avi-590 — De multiples vulnérabilités ont été découvertes dans les produits
Mozilla. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-590</link>
      <description>certfr-2022-avi-590</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-590</guid>
    </item>
    <item>
      <title>EUVD-2026-230074</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-230074</link>
      <description>EUVD-2026-230074</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-230074</guid>
    </item>
    <item>
      <title>fkie_cve-2022-2226</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2226</link>
      <description>&lt;p&gt;An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email&amp;#39;s date will be shown. If the dates were different, then Thunderbird didn&amp;#39;t report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature&amp;#39;s date roughly matches the displayed date of the email. This vulnerability affects Thunderbird &amp;lt; 102 and Thunderbird &amp;lt; 91.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email&amp;#39;s date will be shown. If the dates were different, then Thunderbird didn&amp;#39;t report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature&amp;#39;s date roughly matches the displayed date of the email. This vulnerability affects Thunderbird &amp;lt; 102 and Thunderbird &amp;lt; 91.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-2226</guid>
    </item>
    <item>
      <title>GHSA-g426-wcxv-272f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g426-wcxv-272f</link>
      <description>&lt;p&gt;An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email&amp;#39;s date will be shown. If the dates were different, then Thunderbird didn&amp;#39;t report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature&amp;#39;s date roughly matches the displayed date of the email. This vulnerability affects Thunderbird &amp;lt; 102 and Thunderbird &amp;lt; 91.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email&amp;#39;s date will be shown. If the dates were different, then Thunderbird didn&amp;#39;t report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature&amp;#39;s date roughly matches the displayed date of the email. This vulnerability affects Thunderbird &amp;lt; 102 and Thunderbird &amp;lt; 91.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g426-wcxv-272f</guid>
    </item>
    <item>
      <title>gsd-2022-2226</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-2226</link>
      <description>gsd-2022-2226</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-2226</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12161-1 — MozillaThunderbird-91.11.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12161-1</link>
      <description>&lt;p&gt;MozillaThunderbird-91.11.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaThunderbird-91.11.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12161-1</guid>
    </item>
    <item>
      <title>RHSA-2022:5473 — Red Hat Security Advisory: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:5473</link>
      <description>&lt;p&gt;Mozilla: Undesired attributes could be set as part of prototype pollution Mozilla: An email with a mismatching OpenPGP signature date was accepted as valid Mozilla: CSP bypass enabling stylesheet injection Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI Mozilla: Use-after-free in nsSHistory Mozilla: Unavailable PAC file resulted in OCSP requests being blocked Mozilla: A popup window could be resized in a way to overlay the address bar with web content Mozilla: Potential integer overflow in ReplaceElementsAt Mozilla: Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mozilla: Undesired attributes could be set as part of prototype pollution Mozilla: An email with a mismatching OpenPGP signature date was accepted as valid Mozilla: CSP bypass enabling stylesheet injection Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI Mozilla: Use-after-free in nsSHistory Mozilla: Unavailable PAC file resulted in OCSP requests being blocked Mozilla: A popup window could be resized in a way to overlay the address bar with web content Mozilla: Potential integer overflow in ReplaceElementsAt Mozilla: Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:5473</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-2226</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2226</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: thunderbird, Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email&amp;#39;s date will be shown. If the dates were different, then Thunderbird didn&amp;#39;t report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature&amp;#39;s date roughly matches the displayed date of the email. This vulnerability affects Thunderbird &amp;lt; 102 and Thunderbird &amp;lt; 91.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: thunderbird, Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email&amp;#39;s date will be shown. If the dates were different, then Thunderbird didn&amp;#39;t report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature&amp;#39;s date roughly matches the displayed date of the email. This vulnerability affects Thunderbird &amp;lt; 102 and Thunderbird &amp;lt; 91.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2226</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0505 — Mozilla Produkte: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0505</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um beliebigen Programmcode auszuführen, einen Denial of Service Zustand durchzuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um beliebigen Programmcode auszuführen, einen Denial of Service Zustand durchzuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0505</guid>
    </item>
  </channel>
</rss>
