VDB

CVE-2016-9079

CVE-2016-9079 PUBLISHED KEV CVSS 7.5 HIGH

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

EPSS 87.42% · 99.7th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
87.42%
99.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSthunderbird0, 1:38.3.0+build1-0ubuntu2, 1:38.5.1+build2-0ubuntu1
Ubuntu:14.04:LTSthunderbird*, 1:24.0+build1-0ubuntu1, 1:24.0+build1-0ubuntu2
Ubuntu:14.04:LTSfirefox*, *, *
Ubuntu:16.04:LTSfirefox42.0+build2-0ubuntu1, 44.0+build3-0ubuntu2, 44.0.1+build1-0ubuntu1

Timeline

  • Nov 29, 2016 VulnCheck KEV Exploitation
  • Nov 30, 2016 CVE Published
  • Nov 30, 2016 PoC Published
  • Dec 2, 2016 VulnCheck KEV Exploitation
  • Jan 24, 2017 PoC Published
  • Feb 8, 2017 VulnCheck XDB Entry
  • Jul 15, 2017 PoC Published
  • Mar 16, 2018 PoC Published
  • Jul 29, 2018 VulnCheck XDB Entry
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›