CVE-2016-9079
published 2018-06-11CVE-2016-9079: A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox…
high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-07-13
Exploited in the wild
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | firefox | < firefox 50.0.2-1 (sid) | firefox 50.0.2-1 (sid) |
| debian | firefox-esr | < firefox 50.0.2-1 (sid) | firefox 50.0.2-1 (sid) |
| mozilla | firefox | < 50.0.2 | 50.0.2 |
| mozilla | firefox | < 45.5.1 | 45.5.1 |
| mozilla | firefox | >= 0 < 50.0.2+build1-0ubuntu0.14.04.1 | 50.0.2+build1-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 50.0.2+build1-0ubuntu0.16.04.1 | 50.0.2+build1-0ubuntu0.16.04.1 |
| mozilla | firefox | >= unspecified < 50.0.2 | 50.0.2 |
| mozilla | firefox_esr | >= unspecified < 45.5.1 | 45.5.1 |
| mozilla | thunderbird | < 45.5.1 | 45.5.1 |
| mozilla | thunderbird | >= 0 < 1:45.5.1+build1-0ubuntu0.14.04.1 | 1:45.5.1+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:45.5.1+build1-0ubuntu0.16.04.1 | 1:45.5.1+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= unspecified < 45.5.1 | 45.5.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv9.8CRITICAL
vulncheck7.5HIGH
cisa7.5HIGH