Back to search
CVE-2022-26485
Published: Dec 22, 2022
Modified: Oct 21, 2025
PUBLISHED
Description
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 97.0.2 |
Mozilla | Firefox ESR | affected unspecified - < 91.6.1 |
Mozilla | Firefox for Android | affected unspecified - < 97.3.0 |
Mozilla | Thunderbird | affected unspecified - < 91.6.2 |
Mozilla | Focus | affected unspecified - < 97.3.0 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now