Vulnerability detail
Enriched intelligence for a single CVE
High
CVE-2016-9079
PUBLISHEDA use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild...
- Vendor
- Mozilla
- Product
- Firefox, Firefox ESR, Thunderbird
- Published
- Jun 11, 2018
- EPSS
- —
Description
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitation status
Exploited in the wild
Recorded 2023-06-22 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- Yes
- Technical impact
- partial
References
- https://www.debian.org/security/2016/dsa-3730
- http://rhn.redhat.com/errata/RHSA-2016-2843.html
- https://security.gentoo.org/glsa/201701-35
- http://www.securitytracker.com/id/1037370
- https://www.exploit-db.com/exploits/42327/
- http://rhn.redhat.com/errata/RHSA-2016-2850.html
- https://www.mozilla.org/security/advisories/mfsa2016-92/
- http://www.securityfocus.com/bid/94591
- https://security.gentoo.org/glsa/201701-15
- https://www.exploit-db.com/exploits/41151/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1321066
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Jun 22, 2023 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/firefox_smil_uaf.rb | Apr 28, 2025 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2021-10-08 21:44:13 UTC · 1 stars
github · Created 2018-07-29 12:55:27 UTC · 7 stars
A demo exploit of CVE-2016-9079 on Ubuntu x64
github · Created 2017-02-08 07:41:37 UTC · 1 stars
CVE-2016-9079 exploit code as it appeared on https://lists.torproject.org/pipermail/tor-talk/2016-November/042639.html
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Metasploit