CVE-2016-9079
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
- Affected products
- Alt Linux, Centos, Firefox Esr, Firefox, Red Hat, Suse, Thunderbird, Tor Browser
- Debian Debian Linux
- = 9.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 87.4% (100th percentile)
- Weakness
- CWE-416
- NVD status
- Analyzed
- Published
- 2018-06-11
CVE-2016-9079 at NVD
16 known exploits for CVE-2016-9079
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2016-9079
CVE-2016-9079
firefox-rce-nssmil
Firefox-CVE-2016-9079
Exploit for Use After Free in Debian Debian_Linux
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution Exploit
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution Exploit
Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution Exploit
Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution
Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution
Firefox 50.0.1 ASM.JS JIT-Spray Remote Code Execution
Mozilla Firefox nsSMILTimeContainer::NotifyTimeChange() Remote Code Execution Exploit
Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)
Firefox nsSMILTimeContainer::NotifyTimeChange() Remote Code Execution
Firefox nsSMILTimeContainer::NotifyTimeChange() RCE
New Firefox/Tor Browser 0-day vulnerability (CVE-2016-9079)