Sploitus

CVE-2022-26485

1 known exploit for CVE-2022-26485

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

Mozilla Firefox
< 91.6.1, 97.0.2
Mozilla Firefox Focus
< 97.3.0
Mozilla Firefox Mobile
< 97.3.0
Mozilla Thunderbird
< 91.6.2
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
14.3% (96th percentile)
Weakness
CWE-416
NVD status
Analyzed
Published
2022-12-22
CVE-2022-26485 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-26485

Proof-of-concept code and exploit modules indexed by Sploitus