<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:01:15 +0000</lastBuildDate>
    <item>
      <title>certa-2012-avi-394 — Quatorze vulnérabilités ont été corrigées dans les produits &lt;span
class="textit"&gt;Mozilla&lt;/span&gt;. Elles permettent de fa…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2012-avi-394</link>
      <description>certa-2012-avi-394</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2012-avi-394</guid>
    </item>
    <item>
      <title>EUVD-2026-110790</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-110790</link>
      <description>EUVD-2026-110790</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-110790</guid>
    </item>
    <item>
      <title>fkie_cve-2012-1963</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2012-1963</link>
      <description>&lt;p&gt;The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly restrict the strings placed into the blocked-uri parameter of a violation report, which allows remote web servers to capture OpenID credentials and OAuth 2.0 access tokens by triggering a violation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly restrict the strings placed into the blocked-uri parameter of a violation report, which allows remote web servers to capture OpenID credentials and OAuth 2.0 access tokens by triggering a violation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2012-1963</guid>
    </item>
    <item>
      <title>GHSA-49qg-xp6c-mm46</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-49qg-xp6c-mm46</link>
      <description>&lt;p&gt;The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly restrict the strings placed into the blocked-uri parameter of a violation report, which allows remote web servers to capture OpenID credentials and OAuth 2.0 access tokens by triggering a violation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly restrict the strings placed into the blocked-uri parameter of a violation report, which allows remote web servers to capture OpenID credentials and OAuth 2.0 access tokens by triggering a violation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-49qg-xp6c-mm46</guid>
    </item>
    <item>
      <title>gsd-2012-1963</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2012-1963</link>
      <description>gsd-2012-1963</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2012-1963</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10071-1 — MozillaFirefox-50.1.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10071-1</link>
      <description>&lt;p&gt;MozillaFirefox-50.1.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaFirefox-50.1.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10071-1</guid>
    </item>
    <item>
      <title>RHSA-2012:1088 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2012:1088</link>
      <description>&lt;p&gt;Mozilla: Miscellaneous memory safety hazards (rv:14.0/ rv:10.0.6) (MFSA 2012-42) Mozilla: Incorrect URL displayed in addressbar through drag and drop (MFSA 2012-43) Mozilla: Gecko memory corruption (MFSA 2012-44) Mozilla: Gecko memory corruption (MFSA 2012-44) Mozilla: Gecko memory corruption (MFSA 2012-44) Mozilla: Gecko memory corruption (MFSA 2012-44) Mozilla: Spoofing issue with location (MFSA 2012-45) Mozilla: Improper filtering of javascript in HTML feed-view (MFSA 2012-47) Mozilla: use-after-free in nsGlobalWindow::PageHidden (MFSA 2012-48) Mozilla: Same-compartment Security Wrappers can be bypassed (MFSA 2012-49) Mozilla: X-Frame-Options header ignored when duplicated (MFSA 2012-51) Mozilla: JSDependentString:: undepend string conversion results in memory corruption (MFSA 2012-52) Mozilla: Content Security Policy 1.0 implementation errors cause data leakage (MFSA 2012-53) Mozilla: Clickjacking of certificate warning page (MFSA 2012-54) Mozilla: feed: URLs with an innerURI inherit security context of page (MFSA 2012-55) Mozilla: XSS and code execution through data: URLs (MFSA 2012-46) Mozilla: Code execution through javascript: URLs (MFSA 2012-56)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mozilla: Miscellaneous memory safety hazards (rv:14.0/ rv:10.0.6) (MFSA 2012-42) Mozilla: Incorrect URL displayed in addressbar through drag and drop (MFSA 2012-43) Mozilla: Gecko memory corruption (MFSA 2012-44) Mozilla: Gecko memory corruption (MFSA 2012-44) Mozilla: Gecko memory corruption (MFSA 2012-44) Mozilla: Gecko memory corruption (MFSA 2012-44) Mozilla: Spoofing issue with location (MFSA 2012-45) Mozilla: Improper filtering of javascript in HTML feed-view (MFSA 2012-47) Mozilla: use-after-free in nsGlobalWindow::PageHidden (MFSA 2012-48) Mozilla: Same-compartment Security Wrappers can be bypassed (MFSA 2012-49) Mozilla: X-Frame-Options header ignored when duplicated (MFSA 2012-51) Mozilla: JSDependentString:: undepend string conversion results in memory corruption (MFSA 2012-52) Mozilla: Content Security Policy 1.0 implementation errors cause data leakage (MFSA 2012-53) Mozilla: Clickjacking of certificate warning page (MFSA 2012-54) Mozilla: feed: URLs with an innerURI inherit security context of page (MFSA 2012-55) Mozilla: XSS and code execution through data: URLs (MFSA 2012-46) Mozilla: Code execution through javascript: URLs (MFSA 2012-56)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2012:1088</guid>
    </item>
  </channel>
</rss>
