peter bassill · operator
$ cve CVE-2016-9079 JSON

CVE-2016-9079 KEV EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 87.4% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-07-13.

Description

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS87.42% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2023-07-13
Public exploityes
Published2018-06-11
Last modified2026-06-17

CISA KEV

NameMozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
Added2023-06-22
Due2023-07-13
Vendor / productMozilla / Firefox, Firefox ESR, and Thunderbird
Ransomware usenone reported

Affected (11)

VendorProduct
debiandebian linux
microsoftwindows
mozillafirefox
mozillathunderbird
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux workstation
torprojecttor

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD