<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:09:50 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:10072 — Important: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:10072</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: Content-Disposition header ignored when a file is included in an embed or object tag (CVE-2025-6430)
  * firefox: Use-after-free in FontFaceSet (CVE-2025-6424)
  * firefox: Incorrect parsing of URLs could have allowed embedding of youtube.com (CVE-2025-6429)
  * firefox: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID (CVE-2025-6425)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: Content-Disposition header ignored when a file is included in an embed or object tag (CVE-2025-6430)
  * firefox: Use-after-free in FontFaceSet (CVE-2025-6424)
  * firefox: Incorrect parsing of URLs could have allowed embedding of youtube.com (CVE-2025-6429)
  * firefox: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID (CVE-2025-6425)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:10072</guid>
    </item>
    <item>
      <title>bdu:2025-07728</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-07728</link>
      <description>bdu:2025-07728</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-07728</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0536 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0536</link>
      <description>certfr-2025-avi-0536</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0536</guid>
    </item>
    <item>
      <title>cnvd-2025-15489</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-15489</link>
      <description>cnvd-2025-15489</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-15489</guid>
    </item>
    <item>
      <title>EUVD-2026-290784</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290784</link>
      <description>EUVD-2026-290784</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290784</guid>
    </item>
    <item>
      <title>fkie_cve-2025-6429</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-6429</link>
      <description>&lt;p&gt;Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-6429</guid>
    </item>
    <item>
      <title>GHSA-8r38-4g4q-hgvw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8r38-4g4q-hgvw</link>
      <description>&lt;p&gt;Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox &amp;lt; 140 and Firefox ESR &amp;lt; 128.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox &amp;lt; 140 and Firefox ESR &amp;lt; 128.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8r38-4g4q-hgvw</guid>
    </item>
    <item>
      <title>OESA-2025-1717 — firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1717</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Mozilla Firefox up to 139 (Web Browser). It has been rated as critical.Using CWE to declare the problem leads to CWE-416. Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.Impacted is confidentiality, integrity, and availability.Upgrading to version 140 eliminates this vulnerability.(CVE-2025-6424)&lt;/p&gt;
&lt;p&gt;An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox &amp;amp;lt; 140, Firefox ESR &amp;amp;lt; 115.25, Firefox ESR &amp;amp;lt; 128.12, Thunderbird &amp;amp;lt; 140, and Thunderbird &amp;amp;lt; 128.12.(CVE-2025-6425)&lt;/p&gt;
&lt;p&gt;Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Mozilla Firefox up to 139 (Web Browser). It has been rated as critical.Using CWE to declare the problem leads to CWE-416. Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.Impacted is confidentiality, integrity, and availability.Upgrading to version 140 eliminates this vulnerability.(CVE-2025-6424)&lt;/p&gt;
&lt;p&gt;An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox &amp;amp;lt; 140, Firefox ESR &amp;amp;lt; 115.25, Firefox ESR &amp;amp;lt; 128.12, Thunderbird &amp;amp;lt; 140, and Thunderbird &amp;amp;lt; 128.12.(CVE-2025-6425)&lt;/p&gt;
&lt;p&gt;Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1717</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15216-1 — firefox-esr-128.12.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15216-1</link>
      <description>&lt;p&gt;firefox-esr-128.12.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox-esr-128.12.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15216-1</guid>
    </item>
    <item>
      <title>RHSA-2025:10073 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:10073</link>
      <description>&lt;p&gt;firefox: thunderbird: Use-after-free in FontFaceSet firefox: thunderbird: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID firefox: thunderbird: Incorrect parsing of URLs could have allowed embedding of youtube.com firefox: thunderbird: Content-Disposition header ignored when a file is included in an embed or object tag&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox: thunderbird: Use-after-free in FontFaceSet firefox: thunderbird: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID firefox: thunderbird: Incorrect parsing of URLs could have allowed embedding of youtube.com firefox: thunderbird: Content-Disposition header ignored when a file is included in an embed or object tag&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:10073</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02123-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02123-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02123-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-6429</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6429</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag.  This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6429</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1395 — Mozilla Firefox: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1395</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Firefox ESR ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Angriff auszulösen, Sicherheitsmaßnahmen zu umgehen oder einen Cross-Site-Scripting-Angriff zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Firefox ESR ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Angriff auszulösen, Sicherheitsmaßnahmen zu umgehen oder einen Cross-Site-Scripting-Angriff zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1395</guid>
    </item>
  </channel>
</rss>
