<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:51:37 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:9118 — Important: libvpx security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:9118</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libvpx, AlmaLinux:9: libvpx-devel&lt;/p&gt;
&lt;p&gt;The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libvpx: Double-free in libvpx encoder (CVE-2025-5283)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libvpx, AlmaLinux:9: libvpx-devel&lt;/p&gt;
&lt;p&gt;The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libvpx: Double-free in libvpx encoder (CVE-2025-5283)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:9118</guid>
    </item>
    <item>
      <title>bdu:2025-06284</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06284</link>
      <description>bdu:2025-06284</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06284</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0455 — De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un pro…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0455</link>
      <description>certfr-2025-avi-0455</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0455</guid>
    </item>
    <item>
      <title>cnvd-2025-11244</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-11244</link>
      <description>cnvd-2025-11244</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-11244</guid>
    </item>
    <item>
      <title>EUVD-2026-257981</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-257981</link>
      <description>EUVD-2026-257981</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-257981</guid>
    </item>
    <item>
      <title>fkie_cve-2025-5283</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-5283</link>
      <description>&lt;p&gt;Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-5283</guid>
    </item>
    <item>
      <title>GHSA-j84v-78j2-55gh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j84v-78j2-55gh</link>
      <description>&lt;p&gt;Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j84v-78j2-55gh</guid>
    </item>
    <item>
      <title>OESA-2025-1592 — libvpx security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1592</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: libvpx, openEuler:20.03-LTS-SP4: libvpx, openEuler:22.03-LTS-SP3: libvpx, openEuler:22.03-LTS-SP4: libvpx, openEuler:24.03-LTS: libvpx&lt;/p&gt;
&lt;p&gt;libvpx provides the VP8/VP9 SDK, which allows you to integrate your applications with the VP8 and VP9 video codecs, high quality, royalty free, open source codecs deployed on millions of computers and devices worldwide.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)(CVE-2025-5283)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: libvpx, openEuler:20.03-LTS-SP4: libvpx, openEuler:22.03-LTS-SP3: libvpx, openEuler:22.03-LTS-SP4: libvpx, openEuler:24.03-LTS: libvpx&lt;/p&gt;
&lt;p&gt;libvpx provides the VP8/VP9 SDK, which allows you to integrate your applications with the VP8 and VP9 video codecs, high quality, royalty free, open source codecs deployed on millions of computers and devices worldwide.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)(CVE-2025-5283)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1592</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15210-1 — chromedriver-138.0.7204.96-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15210-1</link>
      <description>&lt;p&gt;chromedriver-138.0.7204.96-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;chromedriver-138.0.7204.96-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15210-1</guid>
    </item>
    <item>
      <title>RHSA-2025:8341 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:8341</link>
      <description>&lt;p&gt;firefox: thunderbird: Error handling for script execution was incorrectly isolated from web content firefox: thunderbird: Potential local code execution in “Copy as cURL” command firefox: thunderbird: Script element events leaked cross-origin resource status firefox: thunderbird: Clickjacking vulnerability could have led to leaking saved payment card details firefox: thunderbird: Memory safety bugs firefox: thunderbird: Memory safety bug libvpx: Double-free in libvpx encoder&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox: thunderbird: Error handling for script execution was incorrectly isolated from web content firefox: thunderbird: Potential local code execution in “Copy as cURL” command firefox: thunderbird: Script element events leaked cross-origin resource status firefox: thunderbird: Clickjacking vulnerability could have led to leaking saved payment card details firefox: thunderbird: Memory safety bugs firefox: thunderbird: Memory safety bug libvpx: Double-free in libvpx encoder&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:8341</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21170-1 — Security update for mozjs128</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21170-1</link>
      <description>&lt;p&gt;Security update for mozjs128&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for mozjs128&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21170-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-5283</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5283</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libvpx, Ubuntu:Pro:18.04:LTS: libvpx, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: libvpx, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: libvpx, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78 and 5 more&lt;/p&gt;
&lt;p&gt;Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libvpx, Ubuntu:Pro:18.04:LTS: libvpx, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: libvpx, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: libvpx, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78 and 5 more&lt;/p&gt;
&lt;p&gt;Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5283</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1158 — Google Chrome / Microsoft Edge: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1158</link>
      <description>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Google Chrome / Microsoft Edge ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Google Chrome / Microsoft Edge ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1158</guid>
    </item>
  </channel>
</rss>
