<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:08:19 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:7672 — Moderate: xdg-utils security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:7672</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: xdg-utils&lt;/p&gt;
&lt;p&gt;The xdg-utils package is a set of simple scripts that provide basic desktop integration functions for any Free Desktop.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments (CVE-2022-4055)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: xdg-utils&lt;/p&gt;
&lt;p&gt;The xdg-utils package is a set of simple scripts that provide basic desktop integration functions for any Free Desktop.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments (CVE-2022-4055)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:7672</guid>
    </item>
    <item>
      <title>bdu:2025-04910</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-04910</link>
      <description>bdu:2025-04910</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-04910</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0524 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0524</link>
      <description>certfr-2025-avi-0524</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0524</guid>
    </item>
    <item>
      <title>EUVD-2026-235753</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-235753</link>
      <description>EUVD-2026-235753</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-235753</guid>
    </item>
    <item>
      <title>fkie_cve-2022-4055</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-4055</link>
      <description>&lt;p&gt;When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-4055</guid>
    </item>
    <item>
      <title>GHSA-p4jr-wm76-h2v3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p4jr-wm76-h2v3</link>
      <description>&lt;p&gt;When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p4jr-wm76-h2v3</guid>
    </item>
    <item>
      <title>gsd-2022-4055</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-4055</link>
      <description>gsd-2022-4055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-4055</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-4055 — When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional head…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-4055</link>
      <description>msrc_CVE-2022-4055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-4055</guid>
    </item>
    <item>
      <title>RHSA-2025:7672 — Red Hat Security Advisory: xdg-utils security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:7672</link>
      <description>&lt;p&gt;xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:7672</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-4055</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-4055</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: xdg-utils, Ubuntu:18.04:LTS: xdg-utils, Ubuntu:20.04:LTS: xdg-utils, Ubuntu:22.04:LTS: xdg-utils, Ubuntu:24.04:LTS: xdg-utils, Ubuntu:25.10: xdg-utils, Ubuntu:26.04:LTS: xdg-utils&lt;/p&gt;
&lt;p&gt;When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: xdg-utils, Ubuntu:18.04:LTS: xdg-utils, Ubuntu:20.04:LTS: xdg-utils, Ubuntu:22.04:LTS: xdg-utils, Ubuntu:24.04:LTS: xdg-utils, Ubuntu:25.10: xdg-utils, Ubuntu:26.04:LTS: xdg-utils&lt;/p&gt;
&lt;p&gt;When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-4055</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1074 — Red Hat Enterprise Linux (xdg-utils): Schwachstelle ermöglicht Umgehung von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1074</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1074</guid>
    </item>
  </channel>
</rss>
