CVE-2016-9079
KEVHIGH 7.5EPSS 87.4%
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 87.42% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2023-06-22
- Published
- 2018-06-11
- Updated
- 2025-10-21
Proof-of-concept exploits (4)
- https://bugzilla.mozilla.org/show_bug.cgi?id=1321066
- LakshmiDesai/CVE-2016-90791★ · 2016-12-07
- dangokyo/CVE-2016-90797★ · 2018-07-29
- soham23/firefox-rce-nssmil1★ · 2026-07-06