<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:26:49 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:1802 — Important: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:1802</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;This update upgrades Thunderbird to version 102.10.0.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Thunderbird: Revocation status of S/Mime recipient certificates was not checked (CVE-2023-0547)
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack (CVE-2023-28427)
* Mozilla: Fullscreen notification obscured (CVE-2023-29533)
* Mozilla: Potential Memory Corruption following Garbage Collector compaction (CVE-2023-29535)
* Mozilla: Invalid free from JavaScript code (CVE-2023-29536)
* Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10 (CVE-2023-29550)
* Mozilla: Memory Corruption in Safe Browsing Code (CVE-2023-1945)
* Thunderbird: Hang when processing certain OpenPGP messages (CVE-2023-29479)
* Mozilla: Content-Disposition filename truncation leads to Reflected File Download (CVE-2023-29539)
* Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux (CVE-2023-29541)
* Mozilla: Incorrect optimization result on ARM64 (CVE-2023-29548)
* MFSA-TMP-2023-0001 Mozilla: Double-free in libwebp (BZ#2186102)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;This update upgrades Thunderbird to version 102.10.0.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Thunderbird: Revocation status of S/Mime recipient certificates was not checked (CVE-2023-0547)
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack (CVE-2023-28427)
* Mozilla: Fullscreen notification obscured (CVE-2023-29533)
* Mozilla: Potential Memory Corruption following Garbage Collector compaction (CVE-2023-29535)
* Mozilla: Invalid free from JavaScript code (CVE-2023-29536)
* Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10 (CVE-2023-29550)
* Mozilla: Memory Corruption in Safe Browsing Code (CVE-2023-1945)
* Thunderbird: Hang when processing certain OpenPGP messages (CVE-2023-29479)
* Mozilla: Content-Disposition filename truncation leads to Reflected File Download (CVE-2023-29539)
* Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux (CVE-2023-29541)
* Mozilla: Incorrect optimization result on ARM64 (CVE-2023-29548)
* MFSA-TMP-2023-0001 Mozilla: Double-free in libwebp (BZ#2186102)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:1802</guid>
    </item>
    <item>
      <title>bdu:2023-01835</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-01835</link>
      <description>bdu:2023-01835</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-01835</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0268 — Une vulnérabilité a été découverte dans &lt;span class="textit"&gt;Mozilla
Thunderbird&lt;/span&gt;. Elle permet à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0268</link>
      <description>certfr-2023-avi-0268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0268</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-KH83435 — matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-kh83435</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: element-web&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the element-web package. matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: element-web&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the element-web package. matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-kh83435</guid>
    </item>
    <item>
      <title>EUVD-2026-218133</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-218133</link>
      <description>EUVD-2026-218133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-218133</guid>
    </item>
    <item>
      <title>fkie_cve-2023-28427</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28427</link>
      <description>&lt;p&gt;matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer&amp;#39;s ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This vulnerability is distinct from GHSA-rfv9-x7hh-xc32 which covers a similar issue. The issue has been patched in matrix-js-sdk 24.0.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer&amp;#39;s ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This vulnerability is distinct from GHSA-rfv9-x7hh-xc32 which covers a similar issue. The issue has been patched in matrix-js-sdk 24.0.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-28427</guid>
    </item>
    <item>
      <title>GHSA-mwq8-fjpf-c2gr — Prototype pollution in matrix-js-sdk (part 2)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mwq8-fjpf-c2gr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: matrix-js-sdk&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-js-sdk functionality, causing denial of service and potentially affecting program logic.&lt;/p&gt;
&lt;p&gt;(This is part 2, where [CVE-2022-36059](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36059) / [GHSA-rfv9-x7hh-xc32](https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-rfv9-x7hh-xc32) is part 1. Part 2 covers remaining vectors not covered by part 1, found in a codebase audit scheduled after part 1.)&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been patched in matrix-js-sdk 24.0.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [Release blog post](https://matrix.org/blog/2023/03/28/security-releases-matrix-js-sdk-24-0-0-and-matrix-react-sdk-3-69-0)
- The advisory [GHSA-rfv9-x7hh-xc32](https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-rfv9-x7hh-xc32) ([CVE-2022-36059](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36059)) refers to an initial set of vulnerable locations discovered and patched in matrix-js-sdk 19.4.0. We opted not to disclose that advisory while we performed an audit of the codebase and are now disclosing it jointly with this one.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory please email us at [security at matrix.org](mailto:security@matrix.org).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: matrix-js-sdk&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-js-sdk functionality, causing denial of service and potentially affecting program logic.&lt;/p&gt;
&lt;p&gt;(This is part 2, where [CVE-2022-36059](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36059) / [GHSA-rfv9-x7hh-xc32](https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-rfv9-x7hh-xc32) is part 1. Part 2 covers remaining vectors not covered by part 1, found in a codebase audit scheduled after part 1.)&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been patched in matrix-js-sdk 24.0.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [Release blog post](https://matrix.org/blog/2023/03/28/security-releases-matrix-js-sdk-24-0-0-and-matrix-react-sdk-3-69-0)
- The advisory [GHSA-rfv9-x7hh-xc32](https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-rfv9-x7hh-xc32) ([CVE-2022-36059](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36059)) refers to an initial set of vulnerable locations discovered and patched in matrix-js-sdk 19.4.0. We opted not to disclose that advisory while we performed an audit of the codebase and are now disclosing it jointly with this one.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory please email us at [security at matrix.org](mailto:security@matrix.org).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mwq8-fjpf-c2gr</guid>
    </item>
    <item>
      <title>gsd-2023-28427</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-28427</link>
      <description>gsd-2023-28427</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-28427</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12823-1 — element-web-1.11.26-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12823-1</link>
      <description>&lt;p&gt;element-web-1.11.26-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;element-web-1.11.26-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12823-1</guid>
    </item>
    <item>
      <title>RHSA-2023:1803 — Red Hat Security Advisory: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1803</link>
      <description>&lt;p&gt;Thunderbird: Revocation status of S/Mime recipient certificates was not checked Mozilla: Memory Corruption in Safe Browsing Code Mozilla: libwebp: Double-free in libwebp Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack Thunderbird: Hang when processing certain OpenPGP messages Mozilla: Fullscreen notification obscured Mozilla: Potential Memory Corruption following Garbage Collector compaction Mozilla: Invalid free from JavaScript code Mozilla: Content-Disposition filename truncation leads to Reflected File Download Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux Mozilla: Incorrect optimization result on ARM64 Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Thunderbird: Revocation status of S/Mime recipient certificates was not checked Mozilla: Memory Corruption in Safe Browsing Code Mozilla: libwebp: Double-free in libwebp Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack Thunderbird: Hang when processing certain OpenPGP messages Mozilla: Fullscreen notification obscured Mozilla: Potential Memory Corruption following Garbage Collector compaction Mozilla: Invalid free from JavaScript code Mozilla: Content-Disposition filename truncation leads to Reflected File Download Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux Mozilla: Incorrect optimization result on ARM64 Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1803</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-28427</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28427</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-matrix-js-sdk, Ubuntu:22.04:LTS: node-matrix-js-sdk, Ubuntu:24.04:LTS: node-matrix-js-sdk&lt;/p&gt;
&lt;p&gt;matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer&amp;#39;s ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This vulnerability is distinct from GHSA-rfv9-x7hh-xc32 which covers a similar issue. The issue has been patched in matrix-js-sdk 24.0.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-matrix-js-sdk, Ubuntu:22.04:LTS: node-matrix-js-sdk, Ubuntu:24.04:LTS: node-matrix-js-sdk&lt;/p&gt;
&lt;p&gt;matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer&amp;#39;s ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This vulnerability is distinct from GHSA-rfv9-x7hh-xc32 which covers a similar issue. The issue has been patched in matrix-js-sdk 24.0.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28427</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0789 — Mozilla Thunderbird: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0789</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Mozilla Thunderbird ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Mozilla Thunderbird ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0789</guid>
    </item>
  </channel>
</rss>
