<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:40:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:8196 — Important: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:8196</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link (CVE-2025-3909)
  * thunderbird: Sender Spoofing via Malformed From Header in Thunderbird (CVE-2025-3875)
  * thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (CVE-2025-3877)
  * thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking (CVE-2025-3932)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link (CVE-2025-3909)
  * thunderbird: Sender Spoofing via Malformed From Header in Thunderbird (CVE-2025-3875)
  * thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (CVE-2025-3877)
  * thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking (CVE-2025-3932)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:8196</guid>
    </item>
    <item>
      <title>bdu:2025-08557</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08557</link>
      <description>bdu:2025-08557</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08557</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0411 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0411</link>
      <description>certfr-2025-avi-0411</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0411</guid>
    </item>
    <item>
      <title>EUVD-2026-290713</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290713</link>
      <description>EUVD-2026-290713</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290713</guid>
    </item>
    <item>
      <title>fkie_cve-2025-3932</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-3932</link>
      <description>&lt;p&gt;It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-3932</guid>
    </item>
    <item>
      <title>GHSA-jfxg-6gv4-f2gh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jfxg-6gv4-f2gh</link>
      <description>&lt;p&gt;It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird &amp;lt; 128.10.1 and Thunderbird &amp;lt; 138.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability affects Thunderbird &amp;lt; 128.10.1 and Thunderbird &amp;lt; 138.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jfxg-6gv4-f2gh</guid>
    </item>
    <item>
      <title>OESA-2025-1835 — thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1835</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Firefox ESR &amp;amp;lt; 115.17, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10458)&lt;/p&gt;
&lt;p&gt;An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Firefox ESR &amp;amp;lt; 115.17, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10459)&lt;/p&gt;
&lt;p&gt;The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10460)&lt;/p&gt;
&lt;p&gt;In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10461)&lt;/p&gt;
&lt;p&gt;Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10462)&lt;/p&gt;
&lt;p&gt;Video frames could have been leaked between origins in some situations. Thi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Firefox ESR &amp;amp;lt; 115.17, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10458)&lt;/p&gt;
&lt;p&gt;An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Firefox ESR &amp;amp;lt; 115.17, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10459)&lt;/p&gt;
&lt;p&gt;The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10460)&lt;/p&gt;
&lt;p&gt;In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10461)&lt;/p&gt;
&lt;p&gt;Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox &amp;amp;lt; 132, Firefox ESR &amp;amp;lt; 128.4, Thunderbird &amp;amp;lt; 128.4, and Thunderbird &amp;amp;lt; 132.(CVE-2024-10462)&lt;/p&gt;
&lt;p&gt;Video frames could have been leaked between origins in some situations. Thi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1835</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15131-1 — MozillaThunderbird-128.10.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15131-1</link>
      <description>&lt;p&gt;MozillaThunderbird-128.10.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaThunderbird-128.10.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15131-1</guid>
    </item>
    <item>
      <title>RHSA-2025:8196 — Red Hat Security Advisory: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:8196</link>
      <description>&lt;p&gt;thunderbird: Sender Spoofing via Malformed From Header in Thunderbird thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;thunderbird: Sender Spoofing via Malformed From Header in Thunderbird thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:8196</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01660-1 — Security update for MozillaThunderbird</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01660-1</link>
      <description>&lt;p&gt;Security update for MozillaThunderbird&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaThunderbird&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01660-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-3932</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3932</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3932</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1062 — Mozilla Thunderbird: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1062</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Thunderbird ausnutzenum beliebigen Programmcode auszuführen, vertrauliche Informationen preiszugeben, einen Denial-of-Service-Zustand herbeizuführen oder Absender-Spoofing durchzuführen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Thunderbird ausnutzenum beliebigen Programmcode auszuführen, vertrauliche Informationen preiszugeben, einen Denial-of-Service-Zustand herbeizuführen oder Absender-Spoofing durchzuführen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1062</guid>
    </item>
  </channel>
</rss>
