CVE-2016-9079
Mozilla Firefox, Mozilla Firefox ESR, Mozilla Thunderbird
Published 11 Jun 2018 · updated 17 Jun 2026 · Analyzed
7.5 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 22 Jun 2023, with a remediation deadline of 13 Jul 2023 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
References
- rhn.redhat.com/errata/RHSA-2016-2843.html · Third Party Advisory
- rhn.redhat.com/errata/RHSA-2016-2850.html · Third Party Advisory
- www.securityfocus.com/bid/94591 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1037370 · Third Party Advisory, VDB Entry
- bugzilla.mozilla.org/show_bug.cgi?id=1321066 · Exploit, Issue Tracking, Vendor Advisory
- security.gentoo.org/glsa/201701-15 · Third Party Advisory
- security.gentoo.org/glsa/201701-35 · Third Party Advisory
- www.debian.org/security/2016/dsa-3730 · Third Party Advisory
- www.exploit-db.com/exploits/41151/ · Exploit, Third Party Advisory, VDB Entry
- www.exploit-db.com/exploits/42327/ · Exploit, Third Party Advisory, VDB Entry
- www.mozilla.org/security/advisories/mfsa2016-92/ · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-9079 · US Government Resource