CyberSec.Space Logo
CVEブラウザに戻る

CVE-2022-26485

🔥 Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2022-12-22
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

Affected Platforms (CPE)

📦
Mozilla

Firefox

< 91.6.1< 97.0.2< 97.3.0
📦
Mozilla

Firefox Focus

< 97.3.0
📦
Mozilla

Thunderbird

< 91.6.2

References & Advisories

関連する脆弱性情報