CVE-2016-9079 KEV EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 87.4% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2023-07-13.
Description
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 87.42% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2023-07-13 |
| Public exploit | yes |
| Published | 2018-06-11 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability |
|---|---|
| Added | 2023-06-22 |
| Due | 2023-07-13 |
| Vendor / product | Mozilla / Firefox, Firefox ESR, and Thunderbird |
| Ransomware use | none reported |
Affected (11)
| Vendor | Product |
|---|---|
| debian | debian linux |
| microsoft | windows |
| mozilla | firefox |
| mozilla | thunderbird |
| redhat | enterprise linux |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server eus |
| redhat | enterprise linux workstation |
| torproject | tor |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution | 2017-07-14 |
| exploit-db | Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit) | 2017-01-24 |
References
- http://rhn.redhat.com/errata/RHSA-2016-2843.html
- http://rhn.redhat.com/errata/RHSA-2016-2850.html
- http://www.securityfocus.com/bid/94591
- http://www.securitytracker.com/id/1037370
- https://bugzilla.mozilla.org/show_bug.cgi?id=1321066
- https://security.gentoo.org/glsa/201701-15
- https://security.gentoo.org/glsa/201701-35
- https://www.debian.org/security/2016/dsa-3730
- https://www.exploit-db.com/exploits/41151/
- https://www.exploit-db.com/exploits/42327/
- https://www.mozilla.org/security/advisories/mfsa2016-92/
- http://rhn.redhat.com/errata/RHSA-2016-2843.html
- http://rhn.redhat.com/errata/RHSA-2016-2850.html
- http://www.securityfocus.com/bid/94591
- http://www.securitytracker.com/id/1037370
- https://bugzilla.mozilla.org/show_bug.cgi?id=1321066
- https://security.gentoo.org/glsa/201701-15
- https://security.gentoo.org/glsa/201701-35
- https://www.debian.org/security/2016/dsa-3730
- https://www.exploit-db.com/exploits/41151/
→ the Explorer · watch your stack · NVD