{
    "id": "CVE-2016-9079",
    "published": "2018-06-11 21:29:01",
    "last_modified": "2026-06-17 00:55:29",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "cwe": "CWE-416",
    "description": "A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.",
    "epss_score": "0.87423",
    "epss_percentile": "0.99753",
    "kev": 1,
    "kev_due": "2023-07-13",
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:22:54",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2023-07-13."
    },
    "products": [
        {
            "vendor": "debian",
            "product": "debian_linux"
        },
        {
            "vendor": "microsoft",
            "product": "windows"
        },
        {
            "vendor": "mozilla",
            "product": "firefox"
        },
        {
            "vendor": "mozilla",
            "product": "thunderbird"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_desktop"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server_aus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server_eus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_workstation"
        },
        {
            "vendor": "torproject",
            "product": "tor"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2016-9079",
        "date_added": "2023-06-22",
        "due_date": "2023-07-13",
        "vendor": "Mozilla",
        "product": "Firefox, Firefox ESR, and Thunderbird",
        "name": "Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability",
        "ransomware": 0
    },
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "42327",
            "title": "Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution",
            "date": "2017-07-14",
            "url": "https://www.exploit-db.com/exploits/42327"
        },
        {
            "source": "exploit-db",
            "ref_id": "41151",
            "title": "Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)",
            "date": "2017-01-24",
            "url": "https://www.exploit-db.com/exploits/41151"
        }
    ],
    "refs_list": [
        "http://rhn.redhat.com/errata/RHSA-2016-2843.html",
        "http://rhn.redhat.com/errata/RHSA-2016-2850.html",
        "http://www.securityfocus.com/bid/94591",
        "http://www.securitytracker.com/id/1037370",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=1321066",
        "https://security.gentoo.org/glsa/201701-15",
        "https://security.gentoo.org/glsa/201701-35",
        "https://www.debian.org/security/2016/dsa-3730",
        "https://www.exploit-db.com/exploits/41151/",
        "https://www.exploit-db.com/exploits/42327/",
        "https://www.mozilla.org/security/advisories/mfsa2016-92/",
        "http://rhn.redhat.com/errata/RHSA-2016-2843.html",
        "http://rhn.redhat.com/errata/RHSA-2016-2850.html",
        "http://www.securityfocus.com/bid/94591",
        "http://www.securitytracker.com/id/1037370",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=1321066",
        "https://security.gentoo.org/glsa/201701-15",
        "https://security.gentoo.org/glsa/201701-35",
        "https://www.debian.org/security/2016/dsa-3730",
        "https://www.exploit-db.com/exploits/41151/",
        "https://www.exploit-db.com/exploits/42327/",
        "https://www.mozilla.org/security/advisories/mfsa2016-92/",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-9079"
    ]
}