<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 10:58:10 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-0239 — Alt-Svc ALPN validation failure when redirected</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-0239</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mozilla Firefox, Mozilla Thunderbird&lt;/p&gt;
&lt;p&gt;When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mozilla Firefox, Mozilla Thunderbird&lt;/p&gt;
&lt;p&gt;When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-0239</guid>
    </item>
    <item>
      <title>USN-7191-1 — firefox vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-7191-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: firefox&lt;/p&gt;
&lt;p&gt;Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2025-0237,
CVE-2025-0239, CVE-2025-0240, CVE-2025-0242, CVE-2025-0243, CVE-2025-0247)&lt;/p&gt;
&lt;p&gt;Irvan Kurniawan discovered that Firefox incorrectly handled memory when
breaking lines in text, leading to a use-after-free vulnerability. An
attacker could possibly use this issue to cause a denial of service or
possibly execute arbitrary code. (CVE-2025-0238)&lt;/p&gt;
&lt;p&gt;Nils Bars discovered that Firefox incorrectly handled memory when using
JavaScript Text Segmentation. An attacker could possibly use this issue to
cause a denial of service. (CVE-2025-0241)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: firefox&lt;/p&gt;
&lt;p&gt;Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2025-0237,
CVE-2025-0239, CVE-2025-0240, CVE-2025-0242, CVE-2025-0243, CVE-2025-0247)&lt;/p&gt;
&lt;p&gt;Irvan Kurniawan discovered that Firefox incorrectly handled memory when
breaking lines in text, leading to a use-after-free vulnerability. An
attacker could possibly use this issue to cause a denial of service or
possibly execute arbitrary code. (CVE-2025-0238)&lt;/p&gt;
&lt;p&gt;Nils Bars discovered that Firefox incorrectly handled memory when using
JavaScript Text Segmentation. An attacker could possibly use this issue to
cause a denial of service. (CVE-2025-0241)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-7191-1</guid>
    </item>
  </channel>
</rss>
