CVE-2016-9079

HIGH KEV

SVG Animation - Use After Free

Title source: llm

Description

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/41151
exploitdb WORKING POC
by Rh0 · htmlremotewindows
https://www.exploit-db.com/exploits/42327
nomisec WORKING POC 7 stars
by dangokyo · client-side
https://github.com/dangokyo/CVE-2016-9079
nomisec WORKING POC 1 stars
by Tau-hub · client-side
https://github.com/Tau-hub/Firefox-CVE-2016-9079
nomisec WORKING POC 1 stars
by LakshmiDesai · client-side
https://github.com/LakshmiDesai/CVE-2016-9079
metasploit WORKING POC NORMAL
by Anonymous Gaijin · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/firefox_smil_uaf.rb

Scores

CVSS v3 7.5
EPSS 0.8481
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CISA KEV 2023-06-22
VulnCheck KEV 2016-11-29
InTheWild.io 2016-11-29
ENISA EUVD EUVD-2016-9900
CWE
CWE-416
Status published
Products (22)
debian/debian_linux 9.0
mozilla/firefox < 45.5.1
mozilla/firefox < 50.0.2
mozilla/thunderbird < 45.5.1
redhat/enterprise_linux 5.0
redhat/enterprise_linux 6.0
redhat/enterprise_linux 7.0
redhat/enterprise_linux_desktop 5.0
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_desktop 7.0
... and 12 more
Published Jun 11, 2018
KEV Added Jun 22, 2023
Tracked Since Feb 18, 2026