cbcvebase.
CVE-2016-9079
published 2018-06-11

CVE-2016-9079: A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-07-13
Exploited in the wild
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianfirefox< firefox 50.0.2-1 (sid)firefox 50.0.2-1 (sid)
debianfirefox-esr< firefox 50.0.2-1 (sid)firefox 50.0.2-1 (sid)
mozillafirefox< 50.0.250.0.2
mozillafirefox< 45.5.145.5.1
mozillafirefox>= 0 < 50.0.2+build1-0ubuntu0.14.04.150.0.2+build1-0ubuntu0.14.04.1
mozillafirefox>= 0 < 50.0.2+build1-0ubuntu0.16.04.150.0.2+build1-0ubuntu0.16.04.1
mozillafirefox>= unspecified < 50.0.250.0.2
mozillafirefox_esr>= unspecified < 45.5.145.5.1
mozillathunderbird< 45.5.145.5.1
mozillathunderbird>= 0 < 1:45.5.1+build1-0ubuntu0.14.04.11:45.5.1+build1-0ubuntu0.14.04.1
mozillathunderbird>= 0 < 1:45.5.1+build1-0ubuntu0.16.04.11:45.5.1+build1-0ubuntu0.16.04.1
mozillathunderbird>= unspecified < 45.5.145.5.1
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv9.8CRITICAL
vulncheck7.5HIGH
cisa7.5HIGH