<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:03:52 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:8726 — Moderate: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:8726</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: History interface could have been used to cause a Denial of Service condition in the browser (CVE-2024-10464)
  * firefox: thunderbird: XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response (CVE-2024-10461)
  * firefox: thunderbird: Permission leak via embed or object elements (CVE-2024-10458)
  * firefox: thunderbird: Use-after-free in layout with accessibility (CVE-2024-10459)
  * firefox: thunderbird: Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4 (CVE-2024-10467)
  * firefox: thunderbird: Clipboard &amp;#34;paste&amp;#34; button persisted across tabs (CVE-2024-10465)
  * firefox: DOM push subscription message could hang Firefox (CVE-2024-10466)
  * firefox: thunderbird: Cross origin video frame leak (CVE-2024-10463)
  * firefox: thunderbird: Origin of permission prompt could be spoofed by long URL (CVE-2024-10462)
  * firefox: thunderbird: Confusing display of origin for external protocol handler prompt (CVE-2024-10460)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: History interface could have been used to cause a Denial of Service condition in the browser (CVE-2024-10464)
  * firefox: thunderbird: XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response (CVE-2024-10461)
  * firefox: thunderbird: Permission leak via embed or object elements (CVE-2024-10458)
  * firefox: thunderbird: Use-after-free in layout with accessibility (CVE-2024-10459)
  * firefox: thunderbird: Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4 (CVE-2024-10467)
  * firefox: thunderbird: Clipboard &amp;#34;paste&amp;#34; button persisted across tabs (CVE-2024-10465)
  * firefox: DOM push subscription message could hang Firefox (CVE-2024-10466)
  * firefox: thunderbird: Cross origin video frame leak (CVE-2024-10463)
  * firefox: thunderbird: Origin of permission prompt could be spoofed by long URL (CVE-2024-10462)
  * firefox: thunderbird: Confusing display of origin for external protocol handler prompt (CVE-2024-10460)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:8726</guid>
    </item>
    <item>
      <title>bdu:2025-00962</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-00962</link>
      <description>bdu:2025-00962</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-00962</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0934 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0934</link>
      <description>certfr-2024-avi-0934</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0934</guid>
    </item>
    <item>
      <title>cnvd-2024-45876</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-45876</link>
      <description>cnvd-2024-45876</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-45876</guid>
    </item>
    <item>
      <title>EUVD-2026-258499</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258499</link>
      <description>EUVD-2026-258499</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258499</guid>
    </item>
    <item>
      <title>fkie_cve-2024-10467</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-10467</link>
      <description>&lt;p&gt;Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-10467</guid>
    </item>
    <item>
      <title>GHSA-9v98-vwhg-6x24</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9v98-vwhg-6x24</link>
      <description>&lt;p&gt;Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9v98-vwhg-6x24</guid>
    </item>
    <item>
      <title>OESA-2024-2342 — firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2342</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Firefox ESR &amp;amp;lt; 115.17, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10458)&#13;
&#13;
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Firefox ESR &amp;amp;lt; 115.17, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10459)&#13;
&#13;
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10460)&#13;
&#13;
In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10461)&#13;
&#13;
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10462)&#13;
&#13;
Video frames co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Firefox ESR &amp;amp;lt; 115.17, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10458)&#13;
&#13;
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Firefox ESR &amp;amp;lt; 115.17, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10459)&#13;
&#13;
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10460)&#13;
&#13;
In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10461)&#13;
&#13;
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10462)&#13;
&#13;
Video frames co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2342</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14438-1 — MozillaThunderbird-128.4.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14438-1</link>
      <description>&lt;p&gt;MozillaThunderbird-128.4.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaThunderbird-128.4.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14438-1</guid>
    </item>
    <item>
      <title>RHSA-2024:8720 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:8720</link>
      <description>&lt;p&gt;firefox: thunderbird: Permission leak via embed or object elements firefox: thunderbird: Use-after-free in layout with accessibility firefox: thunderbird: Confusing display of origin for external protocol handler prompt firefox: thunderbird: XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response firefox: thunderbird: Origin of permission prompt could be spoofed by long URL firefox: thunderbird: Cross origin video frame leak firefox: thunderbird: History interface could have been used to cause a Denial of Service condition in the browser firefox: thunderbird: Clipboard &amp;#34;paste&amp;#34; button persisted across tabs firefox: DOM push subscription message could hang Firefox firefox: thunderbird: Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox: thunderbird: Permission leak via embed or object elements firefox: thunderbird: Use-after-free in layout with accessibility firefox: thunderbird: Confusing display of origin for external protocol handler prompt firefox: thunderbird: XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response firefox: thunderbird: Origin of permission prompt could be spoofed by long URL firefox: thunderbird: Cross origin video frame leak firefox: thunderbird: History interface could have been used to cause a Denial of Service condition in the browser firefox: thunderbird: Clipboard &amp;#34;paste&amp;#34; button persisted across tabs firefox: DOM push subscription message could hang Firefox firefox: thunderbird: Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:8720</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3899-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3899-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3899-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-10467</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-10467</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102 and 1 more&lt;/p&gt;
&lt;p&gt;Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102 and 1 more&lt;/p&gt;
&lt;p&gt;Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 132, Firefox ESR &amp;lt; 128.4, Thunderbird &amp;lt; 128.4, and Thunderbird &amp;lt; 132.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-10467</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3296 — Mozilla Firefox, ESR und Thunderbird: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3296</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen preiszugeben oder einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen preiszugeben oder einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3296</guid>
    </item>
  </channel>
</rss>
