CVE-2022-1196: Use After Free
After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2022-1196.
What is the severity level of CVE-2022-1196?
CVE-2022-1196 has a severity level of medium.
Which software products are affected by CVE-2022-1196?
CVE-2022-1196 affects Mozilla Firefox ESR version up to 91.8 and Mozilla Thunderbird version up to 91.8.
What is the potential impact of CVE-2022-1196?
CVE-2022-1196 can lead to a use-after-free and potentially exploitable crash.
Where can I find more information about CVE-2022-1196?
You can find more information about CVE-2022-1196 at the following references: [Reference 1](https://bugzilla.mozilla.org/show_bug.cgi?id=1750679), [Reference 2](https://www.mozilla.org/en-US/security/advisories/mfsa2022-15/), [Reference 3](https://www.mozilla.org/en-US/security/advisories/mfsa2022-14/).