Vulnerabilities > CVE-2022-1196 - Use After Free vulnerability in Mozilla Firefox ESR

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
mozilla
CWE-416

Summary

After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8.

Vulnerable Configurations

Part Description Count
Application
Mozilla
623

Common Weakness Enumeration (CWE)