<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:57:55 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-06469</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06469</link>
      <description>bdu:2024-06469</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06469</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0656 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0656</link>
      <description>certfr-2024-avi-0656</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0656</guid>
    </item>
    <item>
      <title>cnvd-2024-37122</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-37122</link>
      <description>cnvd-2024-37122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-37122</guid>
    </item>
    <item>
      <title>EUVD-2026-223622</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-223622</link>
      <description>EUVD-2026-223622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-223622</guid>
    </item>
    <item>
      <title>fkie_cve-2024-7531</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-7531</link>
      <description>&lt;p&gt;Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox &amp;lt; 129, Firefox ESR &amp;lt; 115.14, and Firefox ESR &amp;lt; 128.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox &amp;lt; 129, Firefox ESR &amp;lt; 115.14, and Firefox ESR &amp;lt; 128.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-7531</guid>
    </item>
    <item>
      <title>GHSA-3jj9-9269-99m2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3jj9-9269-99m2</link>
      <description>&lt;p&gt;Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox &amp;lt; 129, Firefox ESR &amp;lt; 115.14, and Firefox ESR &amp;lt; 128.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox &amp;lt; 129, Firefox ESR &amp;lt; 115.14, and Firefox ESR &amp;lt; 128.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3jj9-9269-99m2</guid>
    </item>
    <item>
      <title>OESA-2024-1976 — firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1976</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is a standalone web browser, designed for standards compliance and performance.  Its functionality can be enhanced via a plethora of extensions.&#13;
&#13;
Security Fix(es):&#13;
&#13;
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user&amp;amp;apos;s system. This vulnerability affects Firefox &amp;amp;lt; 127, Firefox ESR &amp;amp;lt; 115.12, and Thunderbird &amp;amp;lt; 115.12.(CVE-2024-5690)&#13;
&#13;
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox &amp;amp;lt; 125, Firefox ESR &amp;amp;lt; 115.12, and Thunderbird &amp;amp;lt; 115.12.(CVE-2024-5702)&#13;
&#13;
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox &amp;amp;lt; 129, Firefox ESR &amp;amp;lt; 115.14, Firefox ESR &amp;amp;lt; 128.1, Thunderbird &amp;amp;lt; 128.1, and Thunderbird &amp;amp;lt; 115.14.(CVE-2024-7519)&#13;
&#13;
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox &amp;amp;lt; 129, Firefox ESR &amp;amp;lt; 115.14, Firefox ESR &amp;amp;lt; 128.1, Thunderbird &amp;amp;lt; 128.1, and Thunderbird &amp;amp;lt; 115.14.(CVE-2024-7521)&#13;
&#13;
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox &amp;amp;lt; 129, Firefox ESR &amp;amp;lt; 115.14, Firefox ESR &amp;amp;lt; 128.1, Thunderbird &amp;amp;lt; 128.1, and Thunderbird &amp;amp;lt; 115.14.(CVE-2024-7522)&#13;
&#13;
It w…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is a standalone web browser, designed for standards compliance and performance.  Its functionality can be enhanced via a plethora of extensions.&#13;
&#13;
Security Fix(es):&#13;
&#13;
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user&amp;amp;apos;s system. This vulnerability affects Firefox &amp;amp;lt; 127, Firefox ESR &amp;amp;lt; 115.12, and Thunderbird &amp;amp;lt; 115.12.(CVE-2024-5690)&#13;
&#13;
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox &amp;amp;lt; 125, Firefox ESR &amp;amp;lt; 115.12, and Thunderbird &amp;amp;lt; 115.12.(CVE-2024-5702)&#13;
&#13;
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox &amp;amp;lt; 129, Firefox ESR &amp;amp;lt; 115.14, Firefox ESR &amp;amp;lt; 128.1, Thunderbird &amp;amp;lt; 128.1, and Thunderbird &amp;amp;lt; 115.14.(CVE-2024-7519)&#13;
&#13;
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox &amp;amp;lt; 129, Firefox ESR &amp;amp;lt; 115.14, Firefox ESR &amp;amp;lt; 128.1, Thunderbird &amp;amp;lt; 128.1, and Thunderbird &amp;amp;lt; 115.14.(CVE-2024-7521)&#13;
&#13;
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox &amp;amp;lt; 129, Firefox ESR &amp;amp;lt; 115.14, Firefox ESR &amp;amp;lt; 128.1, Thunderbird &amp;amp;lt; 128.1, and Thunderbird &amp;amp;lt; 115.14.(CVE-2024-7522)&#13;
&#13;
It w…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1976</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14260-1 — MozillaFirefox-129.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14260-1</link>
      <description>&lt;p&gt;MozillaFirefox-129.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaFirefox-129.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14260-1</guid>
    </item>
    <item>
      <title>RHSA-2024:6839 — Red Hat Security Advisory: firefox  update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6839</link>
      <description>&lt;p&gt;nss: vulnerable to Minerva side-channel information leak Mozilla: Memory corruption in NSS mozilla: nss: PK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel Sandy Bridge machines mozilla: Type Confusion in Async Generators in Javascript Engine mozilla: Type confusion when looking up a property name in a &amp;amp;quot;with&amp;amp;quot; block mozilla: Internal event interfaces were exposed to web content when browser EventHandler listener callbacks ran mozilla: Firefox did not ask before openings news: links in an external application mozilla: Garbage collection could mis-color cross-compartment objects in OOM conditions mozilla: WASM type confusion involving ArrayTypes mozilla: SelectElements could be shown over another site if popups are allowed mozilla: Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nss: vulnerable to Minerva side-channel information leak Mozilla: Memory corruption in NSS mozilla: nss: PK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel Sandy Bridge machines mozilla: Type Confusion in Async Generators in Javascript Engine mozilla: Type confusion when looking up a property name in a &amp;amp;quot;with&amp;amp;quot; block mozilla: Internal event interfaces were exposed to web content when browser EventHandler listener callbacks ran mozilla: Firefox did not ask before openings news: links in an external application mozilla: Garbage collection could mis-color cross-compartment objects in OOM conditions mozilla: WASM type confusion involving ArrayTypes mozilla: SelectElements could be shown over another site if popups are allowed mozilla: Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6839</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2876-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2876-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2876-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-7531</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-7531</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox &amp;lt; 129, Firefox ESR &amp;lt; 115.14, and Firefox ESR &amp;lt; 128.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox &amp;lt; 129, Firefox ESR &amp;lt; 115.14, and Firefox ESR &amp;lt; 128.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-7531</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1783 — Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1783</link>
      <description>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um einen Spoofing-Angriff durchzuführen, beliebigen Code auszuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um einen Spoofing-Angriff durchzuführen, beliebigen Code auszuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1783</guid>
    </item>
  </channel>
</rss>
