<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:51:15 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:7552 — Important: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:7552</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* thunderbird: 115.16/128.3 ()
* firefox: thunderbird: Specially crafted WebTransport requests could lead to denial of service (CVE-2024-9399)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131 and Thunderbird 131 (CVE-2024-9403)
* firefox: thunderbird: Potential directory upload bypass via clickjacking (CVE-2024-9397)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 (CVE-2024-9401)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 (CVE-2024-9402)
* firefox: thunderbird: External protocol handlers could be enumerated via popups (CVE-2024-9398)
* firefox: thunderbird: Potential memory corruption during JIT compilation (CVE-2024-9400)
* firefox: thunderbird: Potential memory corruption may occur when cloning certain objects (CVE-2024-9396)
* firefox: thunderbird: Cross-origin access to PDF contents through multipart responses (CVE-2024-9393)
* firefox: thunderbird: Cross-origin access to JSON contents through multipart responses (CVE-2024-9394)
* firefox: thunderbird: Compromised content process can bypass site isolation (CVE-2024-9392)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References sect…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* thunderbird: 115.16/128.3 ()
* firefox: thunderbird: Specially crafted WebTransport requests could lead to denial of service (CVE-2024-9399)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131 and Thunderbird 131 (CVE-2024-9403)
* firefox: thunderbird: Potential directory upload bypass via clickjacking (CVE-2024-9397)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 (CVE-2024-9401)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 (CVE-2024-9402)
* firefox: thunderbird: External protocol handlers could be enumerated via popups (CVE-2024-9398)
* firefox: thunderbird: Potential memory corruption during JIT compilation (CVE-2024-9400)
* firefox: thunderbird: Potential memory corruption may occur when cloning certain objects (CVE-2024-9396)
* firefox: thunderbird: Cross-origin access to PDF contents through multipart responses (CVE-2024-9393)
* firefox: thunderbird: Cross-origin access to JSON contents through multipart responses (CVE-2024-9394)
* firefox: thunderbird: Compromised content process can bypass site isolation (CVE-2024-9392)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References sect…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:7552</guid>
    </item>
    <item>
      <title>bdu:2024-09311</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-09311</link>
      <description>bdu:2024-09311</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-09311</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0829 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0829</link>
      <description>certfr-2024-avi-0829</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0829</guid>
    </item>
    <item>
      <title>cnvd-2024-44474</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-44474</link>
      <description>cnvd-2024-44474</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-44474</guid>
    </item>
    <item>
      <title>EUVD-2026-223455</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-223455</link>
      <description>EUVD-2026-223455</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-223455</guid>
    </item>
    <item>
      <title>fkie_cve-2024-9398</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-9398</link>
      <description>&lt;p&gt;By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox &amp;lt; 131, Firefox ESR &amp;lt; 128.3, Thunderbird &amp;lt; 128.3, and Thunderbird &amp;lt; 131.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox &amp;lt; 131, Firefox ESR &amp;lt; 128.3, Thunderbird &amp;lt; 128.3, and Thunderbird &amp;lt; 131.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-9398</guid>
    </item>
    <item>
      <title>GHSA-3qpq-hc75-5535</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3qpq-hc75-5535</link>
      <description>&lt;p&gt;By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox &amp;lt; 131, Firefox ESR &amp;lt; 128.3, Thunderbird &amp;lt; 128.3, and Thunderbird &amp;lt; 131.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox &amp;lt; 131, Firefox ESR &amp;lt; 128.3, Thunderbird &amp;lt; 128.3, and Thunderbird &amp;lt; 131.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3qpq-hc75-5535</guid>
    </item>
    <item>
      <title>OESA-2024-2241 — firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2241</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is a standalone web browser, designed for standards compliance and performance.  Its functionality can be enhanced via a plethora of extensions.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox &amp;amp;lt; 130, Firefox ESR &amp;amp;lt; 128.2, and Thunderbird &amp;amp;lt; 128.2.(CVE-2024-8385)&#13;
&#13;
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox &amp;amp;lt; 130, Firefox ESR &amp;amp;lt; 128.2, and Thunderbird &amp;amp;lt; 128.2.(CVE-2024-8386)&#13;
&#13;
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;amp;lt; 130, Firefox ESR &amp;amp;lt; 128.2, and Thunderbird &amp;amp;lt; 128.2.(CVE-2024-8387)&#13;
&#13;
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox &amp;amp;lt; 131, Firefox ESR &amp;amp;lt; 128.3, Firefox ESR &amp;amp;lt; 115.16, Thunderbird &amp;amp;lt; 128.3, and Thunderbird &amp;amp;lt; 131.(CVE-2024-9392)&#13;
&#13;
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulner…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is a standalone web browser, designed for standards compliance and performance.  Its functionality can be enhanced via a plethora of extensions.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox &amp;amp;lt; 130, Firefox ESR &amp;amp;lt; 128.2, and Thunderbird &amp;amp;lt; 128.2.(CVE-2024-8385)&#13;
&#13;
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox &amp;amp;lt; 130, Firefox ESR &amp;amp;lt; 128.2, and Thunderbird &amp;amp;lt; 128.2.(CVE-2024-8386)&#13;
&#13;
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;amp;lt; 130, Firefox ESR &amp;amp;lt; 128.2, and Thunderbird &amp;amp;lt; 128.2.(CVE-2024-8387)&#13;
&#13;
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox &amp;amp;lt; 131, Firefox ESR &amp;amp;lt; 128.3, Firefox ESR &amp;amp;lt; 115.16, Thunderbird &amp;amp;lt; 128.3, and Thunderbird &amp;amp;lt; 131.(CVE-2024-9392)&#13;
&#13;
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulner…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2241</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14385-1 — MozillaFirefox-131.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14385-1</link>
      <description>&lt;p&gt;MozillaFirefox-131.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaFirefox-131.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14385-1</guid>
    </item>
    <item>
      <title>RHSA-2024:7621 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:7621</link>
      <description>&lt;p&gt;firefox: Clipboard write permission bypass firefox: thunderbird: Compromised content process can bypass site isolation firefox: thunderbird: Cross-origin access to PDF contents through multipart responses firefox: thunderbird: Cross-origin access to JSON contents through multipart responses firefox: thunderbird: Potential memory corruption may occur when cloning certain objects firefox: thunderbird: Potential directory upload bypass via clickjacking firefox: thunderbird: External protocol handlers could be enumerated via popups firefox: thunderbird: Specially crafted WebTransport requests could lead to denial of service firefox: thunderbird: Potential memory corruption during JIT compilation firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 firefox: thunderbird: Memory safety bugs fixed in Firefox 131 and Thunderbird 131&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox: Clipboard write permission bypass firefox: thunderbird: Compromised content process can bypass site isolation firefox: thunderbird: Cross-origin access to PDF contents through multipart responses firefox: thunderbird: Cross-origin access to JSON contents through multipart responses firefox: thunderbird: Potential memory corruption may occur when cloning certain objects firefox: thunderbird: Potential directory upload bypass via clickjacking firefox: thunderbird: External protocol handlers could be enumerated via popups firefox: thunderbird: Specially crafted WebTransport requests could lead to denial of service firefox: thunderbird: Potential memory corruption during JIT compilation firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 firefox: thunderbird: Memory safety bugs fixed in Firefox 131 and Thunderbird 131&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:7621</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3518-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3518-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3518-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-9398</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-9398</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102 and 1 more&lt;/p&gt;
&lt;p&gt;By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox &amp;lt; 131, Firefox ESR &amp;lt; 128.3, Thunderbird &amp;lt; 128.3, and Thunderbird &amp;lt; 131.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102 and 1 more&lt;/p&gt;
&lt;p&gt;By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox &amp;lt; 131, Firefox ESR &amp;lt; 128.3, Thunderbird &amp;lt; 128.3, and Thunderbird &amp;lt; 131.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-9398</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3057 — Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3057</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Thunderbird ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu erzeugen und vertrauliche Informationen preiszugeben.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Thunderbird ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu erzeugen und vertrauliche Informationen preiszugeben.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3057</guid>
    </item>
  </channel>
</rss>
