<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:01:32 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:70642 — Important: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:70642</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)
  * firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)
  * firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)
  * firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)
  * firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)
  * firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)
  * firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)
  * firefox: Use-after-free in the DOM: Core &amp;amp; HTML component (CVE-2026-84124)
  * firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)
  * firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)
  * thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)
  * thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)
  * thunderbird: One byte overflow read in mail parser (CVE-2026-84640)
  * firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)
  * firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)
  * firefox: thunderbird: U…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)
  * firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)
  * firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)
  * firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)
  * firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)
  * firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)
  * firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)
  * firefox: Use-after-free in the DOM: Core &amp;amp; HTML component (CVE-2026-84124)
  * firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)
  * firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)
  * thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)
  * thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)
  * thunderbird: One byte overflow read in mail parser (CVE-2026-84640)
  * firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)
  * firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)
  * firefox: thunderbird: U…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:70642</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1183 — De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1183</link>
      <description>certfr-2026-avi-1183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1183</guid>
    </item>
    <item>
      <title>EUVD-2026-373607</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-373607</link>
      <description>EUVD-2026-373607</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-373607</guid>
    </item>
    <item>
      <title>fkie_cve-2026-92239</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92239</link>
      <description>&lt;p&gt;A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-92239</guid>
    </item>
    <item>
      <title>GHSA-3f4g-x8c6-4887</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3f4g-x8c6-4887</link>
      <description>&lt;p&gt;A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3f4g-x8c6-4887</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11827-1 — MozillaThunderbird-140.16.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11827-1</link>
      <description>&lt;p&gt;MozillaThunderbird-140.16.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaThunderbird-140.16.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11827-1</guid>
    </item>
    <item>
      <title>RLSA-2026:70642 — Important: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:70642</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)&lt;/p&gt;
&lt;p&gt;* firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the DOM: Core &amp;amp; HTML component (CVE-2026-84124)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)&lt;/p&gt;
&lt;p&gt;* thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)&lt;/p&gt;
&lt;p&gt;* thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)&lt;/p&gt;
&lt;p&gt;* thunderbird: One byte overflow read in mail parser (CVE-2026-84640)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)&lt;/p&gt;
&lt;p&gt;* firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the DOM: Core &amp;amp; HTML component (CVE-2026-84124)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)&lt;/p&gt;
&lt;p&gt;* thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)&lt;/p&gt;
&lt;p&gt;* thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)&lt;/p&gt;
&lt;p&gt;* thunderbird: One byte overflow read in mail parser (CVE-2026-84640)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:70642</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-92239</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-92239</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-92239</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3375 — Mozilla Firefox und Thunderbird: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3375</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Firefox ESR und Thunderbird ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren, den Speicher zu beschädigen, Denial-of-Service-Zustände zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Firefox ESR und Thunderbird ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren, den Speicher zu beschädigen, Denial-of-Service-Zustände zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3375</guid>
    </item>
  </channel>
</rss>
