<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:27:04 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:58897 — Important: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:58897</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983)
  * firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934)
  * firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953)
  * firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987)
  * firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948)
  * firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943)
  * firefox: thunderbird: Information disclosure in the DOM: UI Events &amp;amp; Focus Handling component (CVE-2026-74971)
  * firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941)
  * firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965)
  * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946)
  * firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973)
  * firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949)
  * firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983)
  * firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934)
  * firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953)
  * firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987)
  * firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948)
  * firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943)
  * firefox: thunderbird: Information disclosure in the DOM: UI Events &amp;amp; Focus Handling component (CVE-2026-74971)
  * firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941)
  * firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965)
  * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946)
  * firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973)
  * firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949)
  * firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:58897</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1054 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1054</link>
      <description>certfr-2026-avi-1054</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1054</guid>
    </item>
    <item>
      <title>EUVD-2026-355404</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355404</link>
      <description>EUVD-2026-355404</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355404</guid>
    </item>
    <item>
      <title>fkie_cve-2026-74964</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-74964</link>
      <description>&lt;p&gt;Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-74964</guid>
    </item>
    <item>
      <title>GHSA-7p8c-3v22-58jp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7p8c-3v22-58jp</link>
      <description>&lt;p&gt;Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7p8c-3v22-58jp</guid>
    </item>
    <item>
      <title>OESA-2026-3556 — firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3556</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.(CVE-2026-74934)&lt;/p&gt;
&lt;p&gt;A privilege escalation vulnerability exists in Mozilla Firefox and Thunderbird in the DOM: Networking component. The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. An attacker could exploit this vulnerability to affect confidentiality, integrity, and availability. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.(CVE-2026-74935)&lt;/p&gt;
&lt;p&gt;Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. %if 0 %global moz_debug_prefix /lib/debug %global moz_debug_dir /lib/debug/ %global uname_m %(uname -m) %global symbols_file_name -.en-US.-%(uname.crashreporter-symbols.zip %global symbols_file_path /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip %global _find_debuginfo_opts -p /lib/debug//-.en-US.-%(uname.crashreporter-symbols.zip -o debugcrashreporter.list %global crashreporter_pkg_name mozilla-crashreporter--debuginfo&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.(CVE-2026-74934)&lt;/p&gt;
&lt;p&gt;A privilege escalation vulnerability exists in Mozilla Firefox and Thunderbird in the DOM: Networking component. The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. An attacker could exploit this vulnerability to affect confidentiality, integrity, and availability. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.(CVE-2026-74935)&lt;/p&gt;
&lt;p&gt;Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3556</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11546-1 — firefox-esr-153.1.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11546-1</link>
      <description>&lt;p&gt;firefox-esr-153.1.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox-esr-153.1.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11546-1</guid>
    </item>
    <item>
      <title>RHSA-2026:64813 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:64813</link>
      <description>&lt;p&gt;firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component firefox: thunderbird: Privilege escalation in the DOM: Networking component firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component firefox: thunderbird: Privilege escalation in the DOM: Navigation component firefox: thunderbird: Use-after-free in the Graphics: Text component firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component firefox: Privilege escalation in the Remote Settings Client component firefox: thunderbird: Use-after-free in the Graphics: ImageLib component firefox: thunderbird: Use-after-free in the DOM: Core &amp;amp; HTML component firefox: thunderbird: Information disclosure in the Graphics: Text component firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component firefox: thunderbird: Information disclosure in the Graphics component firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component firefox: thunderbird: Privilege escalation in the Networking: Cookies component firefox: thunderbird: Mitigation bypass in the Safe Browsing component firefox: thunderbird: Mitigation bypass in the Storage: Cache API component firefox: thunderbird: Site isolation issue in the WebExtensions component firefox: Site isolation issue in the Networking: Cookies component firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component f…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component firefox: thunderbird: Privilege escalation in the DOM: Networking component firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component firefox: thunderbird: Privilege escalation in the DOM: Navigation component firefox: thunderbird: Use-after-free in the Graphics: Text component firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component firefox: Privilege escalation in the Remote Settings Client component firefox: thunderbird: Use-after-free in the Graphics: ImageLib component firefox: thunderbird: Use-after-free in the DOM: Core &amp;amp; HTML component firefox: thunderbird: Information disclosure in the Graphics: Text component firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component firefox: thunderbird: Information disclosure in the Graphics component firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component firefox: thunderbird: Privilege escalation in the Networking: Cookies component firefox: thunderbird: Mitigation bypass in the Safe Browsing component firefox: thunderbird: Mitigation bypass in the Storage: Cache API component firefox: thunderbird: Site isolation issue in the WebExtensions component firefox: Site isolation issue in the Networking: Cookies component firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component f…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:64813</guid>
    </item>
    <item>
      <title>RLSA-2026:58897 — Important: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:58897</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Information disclosure in the DOM: UI Events &amp;amp; Focus Handling component (CVE-2026-74971)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941)&lt;/p&gt;
&lt;p&gt;* firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946)&lt;/p&gt;
&lt;p&gt;* firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 15…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Information disclosure in the DOM: UI Events &amp;amp; Focus Handling component (CVE-2026-74971)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941)&lt;/p&gt;
&lt;p&gt;* firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946)&lt;/p&gt;
&lt;p&gt;* firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 15…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:58897</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23304-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23304-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23304-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-74964</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74964</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74964</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2911 — Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2911</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Firefox ESR und Thunderbird ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Spoofing- oder Clickjacking-Angriffe durchzuführen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Firefox ESR und Thunderbird ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Spoofing- oder Clickjacking-Angriffe durchzuführen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2911</guid>
    </item>
  </channel>
</rss>
