CVE-2022-26485
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Firefox, Firefox Esr, Firefox For Android, Focus
- Mozilla Firefox
- < 91.6.1, 97.0.2
- Mozilla Firefox Focus
- < 97.3.0
- Mozilla Firefox Mobile
- < 97.3.0
- Mozilla Thunderbird
- < 91.6.2
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 14.3% (96th percentile)
- Weakness
- CWE-416
- NVD status
- Analyzed
- Published
- 2022-12-22
CVE-2022-26485 at NVD
1 known exploit for CVE-2022-26485
Proof-of-concept code and exploit modules indexed by Sploitus