HIGH
CVE-2022-26485
CVSS
8.8
KEV
Description
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Summary dbcve.org
A use-after-free vulnerability exists in Firefox, Firefox ESR, Thunderbird, and Focus when an XSLT parameter is removed during processing, leading to exploitable memory corruption. In-the-wild exploitation has been reported.
Mitigation
Apply vendor-supplied updates: Firefox 97.0.2, Firefox ESR 91.6.1, Thunderbird 91.6.2, and Focus 97.3.0 or later.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
14.26%
Probability of exploitation in next 30 days
96.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.