<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:25:47 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:1493 — Moderate: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:1493</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;This update upgrades Thunderbird to version 115.9.0.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nss: timing attack against RSA decryption (CVE-2023-5388)
* Mozilla: Crash in NSS TLS method (CVE-2024-0743)
* Mozilla: Leaking of encrypted email subjects to other conversations  (CVE-2024-1936)
* Mozilla: JIT code failed to save return registers on Armv7-A (CVE-2024-2607)
* Mozilla: Integer overflow could have led to out of bounds write
(CVE-2024-2608)
* Mozilla: Improper handling of html and body tags enabled CSP nonce leakage
(CVE-2024-2610)
* Mozilla: Clickjacking vulnerability could have led to a user accidentally
granting permissions (CVE-2024-2611)
* Mozilla: Self referencing object could have potentially led to a
use-after-free (CVE-2024-2612)
* Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and
Thunderbird 115.9 (CVE-2024-2614)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;This update upgrades Thunderbird to version 115.9.0.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nss: timing attack against RSA decryption (CVE-2023-5388)
* Mozilla: Crash in NSS TLS method (CVE-2024-0743)
* Mozilla: Leaking of encrypted email subjects to other conversations  (CVE-2024-1936)
* Mozilla: JIT code failed to save return registers on Armv7-A (CVE-2024-2607)
* Mozilla: Integer overflow could have led to out of bounds write
(CVE-2024-2608)
* Mozilla: Improper handling of html and body tags enabled CSP nonce leakage
(CVE-2024-2610)
* Mozilla: Clickjacking vulnerability could have led to a user accidentally
granting permissions (CVE-2024-2611)
* Mozilla: Self referencing object could have potentially led to a
use-after-free (CVE-2024-2612)
* Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and
Thunderbird 115.9 (CVE-2024-2614)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:1493</guid>
    </item>
    <item>
      <title>bdu:2024-02159</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02159</link>
      <description>bdu:2024-02159</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02159</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0183 — Une vulnérabilité a été découverte dans &lt;span class="textit"&gt;les
produits Mozilla&lt;/span&gt;. Elle permet à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0183</link>
      <description>certfr-2024-avi-0183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0183</guid>
    </item>
    <item>
      <title>cnvd-2024-25572</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-25572</link>
      <description>cnvd-2024-25572</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-25572</guid>
    </item>
    <item>
      <title>EUVD-2026-204268</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-204268</link>
      <description>EUVD-2026-204268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-204268</guid>
    </item>
    <item>
      <title>fkie_cve-2024-1936</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-1936</link>
      <description>&lt;p&gt;The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird&amp;#39;s local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird &amp;lt; 115.8.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird&amp;#39;s local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird &amp;lt; 115.8.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-1936</guid>
    </item>
    <item>
      <title>GHSA-8v87-67f4-56h2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8v87-67f4-56h2</link>
      <description>&lt;p&gt;The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird&amp;#39;s local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird &amp;lt; 115.8.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird&amp;#39;s local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird &amp;lt; 115.8.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8v87-67f4-56h2</guid>
    </item>
    <item>
      <title>gsd-2024-1936</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-1936</link>
      <description>gsd-2024-1936</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-1936</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13753-1 — MozillaThunderbird-115.8.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13753-1</link>
      <description>&lt;p&gt;MozillaThunderbird-115.8.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaThunderbird-115.8.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13753-1</guid>
    </item>
    <item>
      <title>RHSA-2024:1492 — Red Hat Security Advisory: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:1492</link>
      <description>&lt;p&gt;nss: timing attack against RSA decryption Mozilla: Crash in NSS TLS method Mozilla: Leaking of encrypted email subjects to other conversations Mozilla: JIT code failed to save return registers on Armv7-A Mozilla: Integer overflow could have led to out of bounds write Mozilla: Improper handling of html and body tags enabled CSP nonce leakage Mozilla: Clickjacking vulnerability could have led to a user accidentally granting permissions Mozilla: Self referencing object could have potentially led to a use-after-free Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9 Mozilla: Improve handling of out-of-memory conditions in ICU&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nss: timing attack against RSA decryption Mozilla: Crash in NSS TLS method Mozilla: Leaking of encrypted email subjects to other conversations Mozilla: JIT code failed to save return registers on Armv7-A Mozilla: Integer overflow could have led to out of bounds write Mozilla: Improper handling of html and body tags enabled CSP nonce leakage Mozilla: Clickjacking vulnerability could have led to a user accidentally granting permissions Mozilla: Self referencing object could have potentially led to a use-after-free Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9 Mozilla: Improve handling of out-of-memory conditions in ICU&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:1492</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:0893-1 — Security update for MozillaThunderbird</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:0893-1</link>
      <description>&lt;p&gt;Security update for MozillaThunderbird&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaThunderbird&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:0893-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-1936</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-1936</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird&amp;#39;s local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird &amp;lt; 115.8.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird&amp;#39;s local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird &amp;lt; 115.8.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-1936</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0545 — Mozilla Thunderbird: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0545</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Mozilla Thunderbird ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Mozilla Thunderbird ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0545</guid>
    </item>
  </channel>
</rss>
