---
cve: "CVE-2016-9079"
severity: "HIGH"
cvss: 7.5
epss: "87.4%"
vendor: "Mozilla"
kev: true
exploited: true
published: "2018-06-11 21:29:01"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T00:17:47+02:00"
---

# CVE-2016-9079

> 7.5 HIGH · ⚠️ CISA KEV (1179 Tage) · 🔓 Exploited · 🧪 PoC

## Beschreibung

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Exploit-Evidenz

- [EDB-41151 — Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)](https://www.exploit-db.com/exploits/41151) ✅
- [EDB-42327 — Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution](https://www.exploit-db.com/exploits/42327)

## Referenzen

- <https://www.debian.org/security/2016/dsa-3730>
- <http://rhn.redhat.com/errata/RHSA-2016-2843.html>
- <https://security.gentoo.org/glsa/201701-35>
- <http://www.securitytracker.com/id/1037370>
- <https://www.exploit-db.com/exploits/42327/>
- <http://rhn.redhat.com/errata/RHSA-2016-2850.html>
- <https://www.mozilla.org/security/advisories/mfsa2016-92/>
- <http://www.securityfocus.com/bid/94591>
- <https://security.gentoo.org/glsa/201701-15>
- <https://www.exploit-db.com/exploits/41151/>
- <https://bugzilla.mozilla.org/show_bug.cgi?id=1321066>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-9079>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2016-9079) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
