<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:42:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:8196 — Important: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:8196</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link (CVE-2025-3909)
  * thunderbird: Sender Spoofing via Malformed From Header in Thunderbird (CVE-2025-3875)
  * thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (CVE-2025-3877)
  * thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking (CVE-2025-3932)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link (CVE-2025-3909)
  * thunderbird: Sender Spoofing via Malformed From Header in Thunderbird (CVE-2025-3875)
  * thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (CVE-2025-3877)
  * thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking (CVE-2025-3932)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:8196</guid>
    </item>
    <item>
      <title>bdu:2025-05735</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-05735</link>
      <description>bdu:2025-05735</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-05735</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0411 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0411</link>
      <description>certfr-2025-avi-0411</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0411</guid>
    </item>
    <item>
      <title>fkie_cve-2025-3877</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-3877</link>
      <description>&lt;p&gt;Rejected reason: This CVE was marked as fixed, but due to other code landing - was not actually fixed.  It was subsequently fixed in CVE-2025-5986.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rejected reason: This CVE was marked as fixed, but due to other code landing - was not actually fixed.  It was subsequently fixed in CVE-2025-5986.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-3877</guid>
    </item>
    <item>
      <title>GHSA-69m9-2g5j-9m4h</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-69m9-2g5j-9m4h</link>
      <description>&lt;p&gt;A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user&amp;#39;s desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird &amp;lt; 128.10.1 and Thunderbird &amp;lt; 138.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user&amp;#39;s desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird &amp;lt; 128.10.1 and Thunderbird &amp;lt; 138.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-69m9-2g5j-9m4h</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15131-1 — MozillaThunderbird-128.10.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15131-1</link>
      <description>&lt;p&gt;MozillaThunderbird-128.10.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaThunderbird-128.10.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15131-1</guid>
    </item>
    <item>
      <title>RHSA-2025:8196 — Red Hat Security Advisory: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:8196</link>
      <description>&lt;p&gt;thunderbird: Sender Spoofing via Malformed From Header in Thunderbird thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;thunderbird: Sender Spoofing via Malformed From Header in Thunderbird thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:8196</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01660-1 — Security update for MozillaThunderbird</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01660-1</link>
      <description>&lt;p&gt;Security update for MozillaThunderbird&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaThunderbird&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01660-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2025-3877</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3877</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.10: thunderbird, Ubuntu:24.04:LTS: thunderbird, Ubuntu:25.04: thunderbird&lt;/p&gt;
&lt;p&gt;Rejected reason: This CVE was marked as fixed, but due to other code landing - was not actually fixed.  It was subsequently fixed in CVE-2025-5986.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.10: thunderbird, Ubuntu:24.04:LTS: thunderbird, Ubuntu:25.04: thunderbird&lt;/p&gt;
&lt;p&gt;Rejected reason: This CVE was marked as fixed, but due to other code landing - was not actually fixed.  It was subsequently fixed in CVE-2025-5986.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3877</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1062 — Mozilla Thunderbird: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1062</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Thunderbird ausnutzenum beliebigen Programmcode auszuführen, vertrauliche Informationen preiszugeben, einen Denial-of-Service-Zustand herbeizuführen oder Absender-Spoofing durchzuführen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Thunderbird ausnutzenum beliebigen Programmcode auszuführen, vertrauliche Informationen preiszugeben, einen Denial-of-Service-Zustand herbeizuführen oder Absender-Spoofing durchzuführen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1062</guid>
    </item>
  </channel>
</rss>
