<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:11:21 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:21280 — Important: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:21280</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: Mitigation bypass in the DOM: Security component (CVE-2025-13018)
  * firefox: Use-after-free in the Audio/Video component (CVE-2025-13014)
  * firefox: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2025-13016)
  * firefox: Same-origin policy bypass in the DOM: Workers component (CVE-2025-13019)
  * firefox: Use-after-free in the WebRTC: Audio/Video component (CVE-2025-13020)
  * firefox: Race condition in the Graphics component (CVE-2025-13012)
  * firefox: Spoofing issue in Firefox (CVE-2025-13015)
  * firefox: Mitigation bypass in the DOM: Core &amp;amp; HTML component (CVE-2025-13013)
  * firefox: Same-origin policy bypass in the DOM: Notifications component (CVE-2025-13017)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: Mitigation bypass in the DOM: Security component (CVE-2025-13018)
  * firefox: Use-after-free in the Audio/Video component (CVE-2025-13014)
  * firefox: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2025-13016)
  * firefox: Same-origin policy bypass in the DOM: Workers component (CVE-2025-13019)
  * firefox: Use-after-free in the WebRTC: Audio/Video component (CVE-2025-13020)
  * firefox: Race condition in the Graphics component (CVE-2025-13012)
  * firefox: Spoofing issue in Firefox (CVE-2025-13015)
  * firefox: Mitigation bypass in the DOM: Core &amp;amp; HTML component (CVE-2025-13013)
  * firefox: Same-origin policy bypass in the DOM: Notifications component (CVE-2025-13017)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:21280</guid>
    </item>
    <item>
      <title>bdu:2025-14545</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14545</link>
      <description>bdu:2025-14545</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14545</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0991 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0991</link>
      <description>certfr-2025-avi-0991</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0991</guid>
    </item>
    <item>
      <title>cnvd-2025-28715</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-28715</link>
      <description>cnvd-2025-28715</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-28715</guid>
    </item>
    <item>
      <title>EUVD-2026-290687</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290687</link>
      <description>EUVD-2026-290687</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290687</guid>
    </item>
    <item>
      <title>fkie_cve-2025-13019</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-13019</link>
      <description>&lt;p&gt;Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-13019</guid>
    </item>
    <item>
      <title>GHSA-mv5g-cf64-38cv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mv5g-cf64-38cv</link>
      <description>&lt;p&gt;Same-origin policy bypass in the DOM: Workers component. This vulnerability affects Firefox &amp;lt; 145 and Firefox ESR &amp;lt; 140.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Same-origin policy bypass in the DOM: Workers component. This vulnerability affects Firefox &amp;lt; 145 and Firefox ESR &amp;lt; 140.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mv5g-cf64-38cv</guid>
    </item>
    <item>
      <title>OESA-2025-2701 — firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2701</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Race condition in the Graphics component. This vulnerability affects Firefox &amp;amp;lt; 145, Firefox ESR &amp;amp;lt; 140.5, and Firefox ESR &amp;amp;lt; 115.30.(CVE-2025-13012)&lt;/p&gt;
&lt;p&gt;Mitigation bypass in the DOM: Core &amp;amp;amp; HTML component. This vulnerability affects Firefox &amp;amp;lt; 145, Firefox ESR &amp;amp;lt; 140.5, Firefox ESR &amp;amp;lt; 115.30, Thunderbird &amp;amp;lt; 145, and Thunderbird &amp;amp;lt; 140.5.(CVE-2025-13013)&lt;/p&gt;
&lt;p&gt;Use-after-free in the Audio/Video component. This vulnerability affects Firefox &amp;amp;lt; 145, Firefox ESR &amp;amp;lt; 140.5, and Firefox ESR &amp;amp;lt; 115.30.(CVE-2025-13014)&lt;/p&gt;
&lt;p&gt;Spoofing issue in Firefox. This vulnerability affects Firefox &amp;amp;lt; 145, Firefox ESR &amp;amp;lt; 140.5, and Firefox ESR &amp;amp;lt; 115.30.(CVE-2025-13015)&lt;/p&gt;
&lt;p&gt;Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox &amp;amp;lt; 145 and Firefox ESR &amp;amp;lt; 140.5.(CVE-2025-13016)&lt;/p&gt;
&lt;p&gt;Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Race condition in the Graphics component. This vulnerability affects Firefox &amp;amp;lt; 145, Firefox ESR &amp;amp;lt; 140.5, and Firefox ESR &amp;amp;lt; 115.30.(CVE-2025-13012)&lt;/p&gt;
&lt;p&gt;Mitigation bypass in the DOM: Core &amp;amp;amp; HTML component. This vulnerability affects Firefox &amp;amp;lt; 145, Firefox ESR &amp;amp;lt; 140.5, Firefox ESR &amp;amp;lt; 115.30, Thunderbird &amp;amp;lt; 145, and Thunderbird &amp;amp;lt; 140.5.(CVE-2025-13013)&lt;/p&gt;
&lt;p&gt;Use-after-free in the Audio/Video component. This vulnerability affects Firefox &amp;amp;lt; 145, Firefox ESR &amp;amp;lt; 140.5, and Firefox ESR &amp;amp;lt; 115.30.(CVE-2025-13014)&lt;/p&gt;
&lt;p&gt;Spoofing issue in Firefox. This vulnerability affects Firefox &amp;amp;lt; 145, Firefox ESR &amp;amp;lt; 140.5, and Firefox ESR &amp;amp;lt; 115.30.(CVE-2025-13015)&lt;/p&gt;
&lt;p&gt;Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox &amp;amp;lt; 145 and Firefox ESR &amp;amp;lt; 140.5.(CVE-2025-13016)&lt;/p&gt;
&lt;p&gt;Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2701</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15735-1 — MozillaFirefox-145.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15735-1</link>
      <description>&lt;p&gt;MozillaFirefox-145.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaFirefox-145.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15735-1</guid>
    </item>
    <item>
      <title>RHSA-2025:21120 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:21120</link>
      <description>&lt;p&gt;firefox: thunderbird: Race condition in the Graphics component firefox: thunderbird: Mitigation bypass in the DOM: Core &amp;amp; HTML component firefox: thunderbird: Use-after-free in the Audio/Video component firefox: thunderbird: Spoofing issue in Firefox firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component firefox: thunderbird: Same-origin policy bypass in the DOM: Notifications component firefox: thunderbird: Mitigation bypass in the DOM: Security component firefox: thunderbird: Same-origin policy bypass in the DOM: Workers component firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox: thunderbird: Race condition in the Graphics component firefox: thunderbird: Mitigation bypass in the DOM: Core &amp;amp; HTML component firefox: thunderbird: Use-after-free in the Audio/Video component firefox: thunderbird: Spoofing issue in Firefox firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component firefox: thunderbird: Same-origin policy bypass in the DOM: Notifications component firefox: thunderbird: Mitigation bypass in the DOM: Security component firefox: thunderbird: Same-origin policy bypass in the DOM: Workers component firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:21120</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21021-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21021-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21021-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-13019</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-13019</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-13019</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2566 — Mozilla Firefox und Firefox ESR: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2566</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Firefox ESR ausnutzen, um beliebigen Code auszuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Daten aus anderen Ursprüngen zu lesen oder aus der Sandbox auszubrechen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Firefox ESR ausnutzen, um beliebigen Code auszuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Daten aus anderen Ursprüngen zu lesen oder aus der Sandbox auszubrechen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2566</guid>
    </item>
  </channel>
</rss>
