<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:15:22 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:11747 — Important: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:11747</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Large branch table could lead to truncated instruction (CVE-2025-8028)
  * firefox: thunderbird: Memory safety bugs (CVE-2025-8035)
  * firefox: thunderbird: Incorrect URL stripping in CSP reports (CVE-2025-8031)
  * firefox: thunderbird: JavaScript engine only wrote partial return value to stack (CVE-2025-8027)
  * firefox: thunderbird: Potential user-assisted code execution in ?Copy as cURL? command (CVE-2025-8030)
  * firefox: Memory safety bugs (CVE-2025-8034)
  * firefox: thunderbird: Incorrect JavaScript state machine for generators (CVE-2025-8033)
  * firefox: thunderbird: XSLT documents could bypass CSP (CVE-2025-8032)
  * firefox: thunderbird: javascript: URLs executed on object and embed tags (CVE-2025-8029)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Large branch table could lead to truncated instruction (CVE-2025-8028)
  * firefox: thunderbird: Memory safety bugs (CVE-2025-8035)
  * firefox: thunderbird: Incorrect URL stripping in CSP reports (CVE-2025-8031)
  * firefox: thunderbird: JavaScript engine only wrote partial return value to stack (CVE-2025-8027)
  * firefox: thunderbird: Potential user-assisted code execution in ?Copy as cURL? command (CVE-2025-8030)
  * firefox: Memory safety bugs (CVE-2025-8034)
  * firefox: thunderbird: Incorrect JavaScript state machine for generators (CVE-2025-8033)
  * firefox: thunderbird: XSLT documents could bypass CSP (CVE-2025-8032)
  * firefox: thunderbird: javascript: URLs executed on object and embed tags (CVE-2025-8029)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:11747</guid>
    </item>
    <item>
      <title>bdu:2025-09459</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09459</link>
      <description>bdu:2025-09459</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09459</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0615 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0615</link>
      <description>certfr-2025-avi-0615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0615</guid>
    </item>
    <item>
      <title>cnvd-2025-20065</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-20065</link>
      <description>cnvd-2025-20065</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-20065</guid>
    </item>
    <item>
      <title>EUVD-2026-290697</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290697</link>
      <description>EUVD-2026-290697</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290697</guid>
    </item>
    <item>
      <title>fkie_cve-2025-8035</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-8035</link>
      <description>&lt;p&gt;Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-8035</guid>
    </item>
    <item>
      <title>GHSA-r69h-f35r-wf4c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r69h-f35r-wf4c</link>
      <description>&lt;p&gt;Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 141, Firefox ESR &amp;lt; 128.13, Firefox ESR &amp;lt; 140.1, Thunderbird &amp;lt; 141, Thunderbird &amp;lt; 128.13, and Thunderbird &amp;lt; 140.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &amp;lt; 141, Firefox ESR &amp;lt; 128.13, Firefox ESR &amp;lt; 140.1, Thunderbird &amp;lt; 141, Thunderbird &amp;lt; 128.13, and Thunderbird &amp;lt; 140.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r69h-f35r-wf4c</guid>
    </item>
    <item>
      <title>OESA-2025-1933 — firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1933</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Mozilla Thunderbird up to 140 on 64-bit (Mail Client Software). It has been classified as critical.CWE is classifying the issue as CWE-252. The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.This is going to have an impact on confidentiality, integrity, and availability.Upgrading to version 141 eliminates this vulnerability.(CVE-2025-8027)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Mozilla Firefox up to 140 on ARM64 (Web Browser). It has been declared as critical.The CWE definition for the vulnerability is CWE-119. The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.As an impact it is known to affect confidentiality, integrity, and availability.Upgrading to version 141 eliminates this vulnerability.(CVE-2025-8028)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Mozilla Thunderbird up to 140 on 64-bit (Mail Client Software). It has been classified as critical.CWE is classifying the issue as CWE-252. The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.This is going to have an impact on confidentiality, integrity, and availability.Upgrading to version 141 eliminates this vulnerability.(CVE-2025-8027)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Mozilla Firefox up to 140 on ARM64 (Web Browser). It has been declared as critical.The CWE definition for the vulnerability is CWE-119. The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.As an impact it is known to affect confidentiality, integrity, and availability.Upgrading to version 141 eliminates this vulnerability.(CVE-2025-8028)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1933</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15371-1 — firefox-esr-140.1.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15371-1</link>
      <description>&lt;p&gt;firefox-esr-140.1.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox-esr-140.1.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15371-1</guid>
    </item>
    <item>
      <title>RHSA-2025:11797 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:11797</link>
      <description>&lt;p&gt;firefox: thunderbird: JavaScript engine only wrote partial return value to stack firefox: thunderbird: Large branch table could lead to truncated instruction firefox: thunderbird: javascript: URLs executed on object and embed tags firefox: thunderbird: Potential user-assisted code execution in “Copy as cURL” command firefox: thunderbird: Incorrect URL stripping in CSP reports firefox: thunderbird: XSLT documents could bypass CSP firefox: thunderbird: Incorrect JavaScript state machine for generators firefox: thunderbird: Memory safety bugs firefox: thunderbird: Memory safety bugs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox: thunderbird: JavaScript engine only wrote partial return value to stack firefox: thunderbird: Large branch table could lead to truncated instruction firefox: thunderbird: javascript: URLs executed on object and embed tags firefox: thunderbird: Potential user-assisted code execution in “Copy as cURL” command firefox: thunderbird: Incorrect URL stripping in CSP reports firefox: thunderbird: XSLT documents could bypass CSP firefox: thunderbird: Incorrect JavaScript state machine for generators firefox: thunderbird: Memory safety bugs firefox: thunderbird: Memory safety bugs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:11797</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02531-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02531-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02531-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-8035</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8035</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8035</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1623 — Mozilla Firefox , Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1623</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen und andere, nicht näher definierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen und andere, nicht näher definierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1623</guid>
    </item>
  </channel>
</rss>
