← Vulnerability feed

Vulnerability record · CVE-2016-9079 · published 11 June 2018

CVE-2016-9079: Firefox and Tor Browser SVG Animation use-after-free

Debian · Debian Linux

A use-after-free flaw in SVG Animation affects Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1. Mozilla reports an exploit built on this vulnerability was found in the wild targeting Firefox and Tor Browser users on Windows, making it a confirmed real-world attack rather than a theoretical bug.

7.5 CVSS 3.1 High CISA KEV since 22 Jun 2023 EPSS 87% · top 0.2% CWE-416 · Use after free
7.5CVSS 3.1 base score, v2 5.0
87%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
10Affected product versions listed by NVD
23References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityConfirmed in-the-wild exploitation, CISA KEV listing, and a 99.7th percentile EPSS score make this an urgent patch target despite the moderate CVSS base score of 7.5.

What it is

A use-after-free flaw in SVG Animation affects Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1. Mozilla reports an exploit built on this vulnerability was found in the wild targeting Firefox and Tor Browser users on Windows, making it a confirmed real-world attack rather than a theoretical bug.

Impact

The CVSS vector rates only confidentiality impact (C:H) with no integrity or availability effect, so the recorded scoring describes information disclosure. However, a use-after-free in a browser rendering path is typically a memory-corruption primitive, and the in-the-wild exploit reports indicate the practical impact can exceed the scored vector.

Attack surface

Reached over the network with no privileges and no user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N), meaning a crafted SVG animation delivered to the browser can trigger the flaw. The description confirms the exploit targeted Firefox and Tor Browser users on Windows.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2023-06-22 with a 2023-07-13 remediation due date, and references carry Exploit tags including Exploit-DB entries 41151 and 42327; EPSS is 0.87423 (99.7th percentile). Exploitation is confirmed in the wild.

What to do

  • Update Firefox to 50.0.2 or later, Firefox ESR to 45.5.1 or later, and Thunderbird to 45.5.1 or later per Mozilla advisory mfsa2016-92.
  • Apply the vendor errata for Linux distributions carrying these packages (Red Hat RHSA-2016-2843 and RHSA-2016-2850, Debian DSA-3730, Gentoo GLSA 201701-15 and 201701-35).
  • Update Tor Browser to a build based on a fixed Firefox ESR, since Tor Browser users were a named target of the in-the-wild exploit.
  • If immediate patching is not possible, restrict browsing to trusted sites and treat unsolicited SVG content as hostile, but note this is a stopgap and not a substitute for the update.

Detection

  • Hunt for Firefox, Firefox ESR, Thunderbird, or Tor Browser versions below the fixed releases (50.0.2, 45.5.1, 45.5.1) across endpoints and report any that remain.
  • Review proxy, IDS, and browser telemetry for SVG or animation content delivered from unusual or low-reputation hosts to Firefox or Tor Browser clients.
  • Look for browser process crashes followed by unexpected child processes or outbound connections, which can indicate a use-after-free exploit chain.
  • Check whether the CISA KEV due date of 2023-07-13 was met in your environment and flag any assets still unpatched past it.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-9079 to the Known Exploited Vulnerabilities catalog on 22 June 2023 as "Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 July 2023.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://rhn.redhat.com/errata/RHSA-2016-2843.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2850.html Third Party Advisory
http://www.securityfocus.com/bid/94591 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037370 Third Party AdvisoryVDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=1321066 ExploitIssue TrackingVendor Advisory
https://security.gentoo.org/glsa/201701-15 Third Party Advisory
https://security.gentoo.org/glsa/201701-35 Third Party Advisory
https://www.debian.org/security/2016/dsa-3730 Third Party Advisory
https://www.exploit-db.com/exploits/41151/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/42327/ ExploitThird Party AdvisoryVDB Entry
https://www.mozilla.org/security/advisories/mfsa2016-92/ Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2016-2843.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2850.html Third Party Advisory
http://www.securityfocus.com/bid/94591 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037370 Third Party AdvisoryVDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=1321066 ExploitIssue TrackingVendor Advisory
https://security.gentoo.org/glsa/201701-15 Third Party Advisory
https://security.gentoo.org/glsa/201701-35 Third Party Advisory
https://www.debian.org/security/2016/dsa-3730 Third Party Advisory
https://www.exploit-db.com/exploits/41151/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/42327/ ExploitThird Party AdvisoryVDB Entry
https://www.mozilla.org/security/advisories/mfsa2016-92/ Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-9079 US Government Resource

Track CVE-2016-9079 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed10.0CVE-2019-11708Mozilla Firefox and Thunderbird sandbox escape via Prompt:Open IPC validation flawThe Prompt:Open IPC message between child and parent processes does not sufficiently vet its parameters, letting a compromised child process cause th…KEVEPSS 56%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2016-9079), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.