<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 06:35:52 +0000</lastBuildDate>
    <item>
      <title>CVE-2015-0834</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2015-0834</link>
      <description>&lt;p&gt;The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2015-0834</guid>
    </item>
    <item>
      <title>USN-2505-1 — firefox vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-2505-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: firefox&lt;/p&gt;
&lt;p&gt;Matthew Noorenberghe discovered that Mozilla domains in the allowlist
could make UITour API calls from background tabs. If one of these domains
were compromised and open in a background tab, an attacker could 
potentially exploit this to conduct clickjacking attacks. (CVE-2015-0819)&lt;/p&gt;
&lt;p&gt;Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)&lt;/p&gt;
&lt;p&gt;Armin Razmdjou discovered that opening hyperlinks with specific mouse
and key combinations could allow a Chrome privileged URL to be opened
without context restrictions being preserved. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to bypass security restrictions. (CVE-2015-0821)&lt;/p&gt;
&lt;p&gt;Armin Razmdjou discovered that contents of locally readable files could
be made available via manipulation of form autocomplete in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to obtain sensitive
information. (CVE-2015-0822)&lt;/p&gt;
&lt;p&gt;Atte Kettunen discovered a use-after-free in the OpenType Sanitiser (OTS)
in some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to cause a
denial of service via application crash. (CVE-2015-0823)&lt;/p&gt;
&lt;p&gt;Atte Kettunen discovered a crash when drawing images using Cairo in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: firefox&lt;/p&gt;
&lt;p&gt;Matthew Noorenberghe discovered that Mozilla domains in the allowlist
could make UITour API calls from background tabs. If one of these domains
were compromised and open in a background tab, an attacker could 
potentially exploit this to conduct clickjacking attacks. (CVE-2015-0819)&lt;/p&gt;
&lt;p&gt;Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)&lt;/p&gt;
&lt;p&gt;Armin Razmdjou discovered that opening hyperlinks with specific mouse
and key combinations could allow a Chrome privileged URL to be opened
without context restrictions being preserved. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to bypass security restrictions. (CVE-2015-0821)&lt;/p&gt;
&lt;p&gt;Armin Razmdjou discovered that contents of locally readable files could
be made available via manipulation of form autocomplete in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to obtain sensitive
information. (CVE-2015-0822)&lt;/p&gt;
&lt;p&gt;Atte Kettunen discovered a use-after-free in the OpenType Sanitiser (OTS)
in some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to cause a
denial of service via application crash. (CVE-2015-0823)&lt;/p&gt;
&lt;p&gt;Atte Kettunen discovered a crash when drawing images using Cairo in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-2505-1</guid>
    </item>
  </channel>
</rss>
