Sploitus

CVE-2022-26384

No indexed exploits for CVE-2022-26384 yet

If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

Mozilla Firefox
< 98.0
Mozilla Firefox Esr
< 91.7
Mozilla Thunderbird
< 91.7
Fix
Available
CVSS 3.1
9.6 CRITICAL
EPSS
0.9% (57th percentile)
Weakness
CWE-693
NVD status
Modified
Published
2022-12-22
CVE-2022-26384 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-26384 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-26384 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.