CVE-2022-1097
NSSToken objects were referenced via direct points, and could have been accessed in an unsafe way on different threads,
NSSToken objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
MEDIUM · CVSS 6.5
EPSS 0.00197
Schedule remediation
- Public exploit or PoC is available
Sigma rules1
YARA rules0