CVE-2016-9079

Mozilla Firefox, Mozilla Firefox ESR, Mozilla Thunderbird

Published 11 Jun 2018 · updated 17 Jun 2026 · Analyzed

7.5 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 22 Jun 2023, with a remediation deadline of 13 Jul 2023 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

References