CVE-2016-9079
HIGH KEVSVG Animation - Use After Free
Title source: llmDescription
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
Exploits (6)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/41151
nomisec
WORKING POC
1 stars
by Tau-hub · client-side
https://github.com/Tau-hub/Firefox-CVE-2016-9079
nomisec
WORKING POC
1 stars
by LakshmiDesai · client-side
https://github.com/LakshmiDesai/CVE-2016-9079
metasploit
WORKING POC
NORMAL
by Anonymous Gaijin · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/firefox_smil_uaf.rb
References (12)
Scores
CVSS v3
7.5
EPSS
0.8481
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CISA KEV
2023-06-22
VulnCheck KEV
2016-11-29
InTheWild.io
2016-11-29
ENISA EUVD
EUVD-2016-9900
CWE
CWE-416
Status
published
Products (22)
debian/debian_linux
9.0
mozilla/firefox
< 45.5.1
mozilla/firefox
< 50.0.2
mozilla/thunderbird
< 45.5.1
redhat/enterprise_linux
5.0
redhat/enterprise_linux
6.0
redhat/enterprise_linux
7.0
redhat/enterprise_linux_desktop
5.0
redhat/enterprise_linux_desktop
6.0
redhat/enterprise_linux_desktop
7.0
... and 12 more
Published
Jun 11, 2018
KEV Added
Jun 22, 2023
Tracked Since
Feb 18, 2026