<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:11:56 +0000</lastBuildDate>
    <item>
      <title>certa-2009-avi-157 — Plusieurs vulnérabilités ont été identifiées dans le navigateur Mozilla
Firefox. L'exploitation de celles-ci peut avoir…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2009-avi-157</link>
      <description>certa-2009-avi-157</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2009-avi-157</guid>
    </item>
    <item>
      <title>EUVD-2026-122337</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-122337</link>
      <description>EUVD-2026-122337</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-122337</guid>
    </item>
    <item>
      <title>fkie_cve-2009-1306</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2009-1306</link>
      <description>&lt;p&gt;The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a &amp;#34;Content-Disposition: attachment&amp;#34; designation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a &amp;#34;Content-Disposition: attachment&amp;#34; designation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2009-1306</guid>
    </item>
    <item>
      <title>GHSA-hh3w-x3wq-8jvq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hh3w-x3wq-8jvq</link>
      <description>&lt;p&gt;The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a &amp;#34;Content-Disposition: attachment&amp;#34; designation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a &amp;#34;Content-Disposition: attachment&amp;#34; designation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hh3w-x3wq-8jvq</guid>
    </item>
    <item>
      <title>gsd-2009-1306</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2009-1306</link>
      <description>gsd-2009-1306</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2009-1306</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10071-1 — MozillaFirefox-50.1.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10071-1</link>
      <description>&lt;p&gt;MozillaFirefox-50.1.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaFirefox-50.1.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10071-1</guid>
    </item>
    <item>
      <title>RHSA-2009:0436 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2009:0436</link>
      <description>&lt;p&gt;firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks) Firefox 3 Layout engine crashes Firefox 2 and 3 Layout engine crash Firefox 3 JavaScript engine crashes Firefox 2 and 3 JavaScript engine crash jar: scheme ignores the content-disposition: header on the inner URI view-source: protocol Firefox XSS hazard using third-party stylesheets and XBL bindings Firefox Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString Firefox Malicious search plugins can inject code into arbitrary sites Firefox POST data sent to wrong site when saving web page with embedded frame javascript: URIs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks) Firefox 3 Layout engine crashes Firefox 2 and 3 Layout engine crash Firefox 3 JavaScript engine crashes Firefox 2 and 3 JavaScript engine crash jar: scheme ignores the content-disposition: header on the inner URI view-source: protocol Firefox XSS hazard using third-party stylesheets and XBL bindings Firefox Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString Firefox Malicious search plugins can inject code into arbitrary sites Firefox POST data sent to wrong site when saving web page with embedded frame javascript: URIs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2009:0436</guid>
    </item>
  </channel>
</rss>
