CVE-2016-9079
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- October 27, 2016
- Published Date
- June 11, 2018
- Last Updated
- February 07, 2025
- Vendor
- Mozilla
- Product
- Firefox, Firefox ESR, Thunderbird
- Description
- A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
CVSS Scores
CVSS v3.1
7.5 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- partial
References
https://www.debian.org/security/2016/dsa-3730
http://rhn.redhat.com/errata/RHSA-2016-2843.html
https://security.gentoo.org/glsa/201701-35
http://www.securitytracker.com/id/1037370
https://www.exploit-db.com/exploits/42327/
http://rhn.redhat.com/errata/RHSA-2016-2850.html
https://www.mozilla.org/security/advisories/mfsa2016-92/
http://www.securityfocus.com/bid/94591
https://security.gentoo.org/glsa/201701-15
https://www.exploit-db.com/exploits/41151/
https://bugzilla.mozilla.org/show_bug.cgi?id=1321066
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2023-06-22 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/firefox_smil_uaf.rb | 2025-04-29 11:01:30 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
firefox_smil_uaf
Type: metasploit • Created: Unknown
Metasploit module for CVE-2016-9079
Tau-hub/Firefox-CVE-2016-9079
Type: github • Created: 2021-10-08 21:44:13 UTC • Stars: 1
dangokyo/CVE-2016-9079
Type: github • Created: 2018-07-29 12:55:27 UTC • Stars: 7
A demo exploit of CVE-2016-9079 on Ubuntu x64
LakshmiDesai/CVE-2016-9079
Type: github • Created: 2017-02-08 07:41:37 UTC • Stars: 1
CVE-2016-9079 exploit code as it appeared on https://lists.torproject.org/pipermail/tor-talk/2016-November/042639.html