CVE-2022-26485High· 8.8▾ Abyssal⚠ Exploited in the wild0dayPoC availableRemoving an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for A…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 2.9 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Federal remediation due Mar 21, 2022
Disclosed via NVD
Last analysed / modified upstream
14%
14% → 14%
1 GitHub repo
Added to the CISA catalog on Mar 7, 2022. Federal remediation due Mar 21, 2022. View catalog ↗
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
firefox < 91.6.1firefox < 97.0.2firefox_focus < 97.3.0firefox_mobile < 97.3.0thunderbird < 91.6.2Upgrade past the affected range:
firefox 97.0.2firefox_focus 97.3.0firefox_mobile 97.3.0thunderbird 91.6.2Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-26486Critical· 9.6An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape
CVE-2024-9680Critical· 9.8An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines
CVE-2026-74943Critical· 9.8Use-after-free in the Graphics: ImageLib component
CVE-2026-74936Critical· 9.8Use-after-free in the JavaScript: WebAssembly component
CVE-2026-74944Critical· 9.8Use-after-free in the DOM: Core & HTML component
CVE-2026-74940Critical· 9.8Use-after-free in the Graphics: Text component