{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2016-9079",
  "revision": 1,
  "title": "Firefox — freed memory in the animation code",
  "summary": "A use-after-free in the animation handling of Firefox and Thunderbird runs an attacker's code. The exploit found in the wild went after people using Firefox and the Tor Browser on Windows.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.5,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "version": "3.1"
  },
  "epss": 0.87423,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2023-06-22",
    "prerequisites": "The user must visit a page the attacker controls."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "Firefox >= 50.0.2",
      "Firefox ESR >= 45.5.1",
      "Thunderbird >= 45.5.1"
    ]
  },
  "mitre_attack": [
    "T1203"
  ],
  "kill_chain": "execution",
  "recommended_action": "Update Firefox past 50.0.2, the extended support release past 45.5.1, and Thunderbird past 45.5.1. Anything older than that is a known, published target.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2016-9079",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2016-9079",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2016-9079",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-9079",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.mozilla.org/security/advisories/mfsa2016-92/"
    },
    {
      "type": "exploit",
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1321066"
    },
    {
      "type": "exploit",
      "url": "https://www.exploit-db.com/exploits/41151/"
    }
  ],
  "published_at": "2018-06-11T21:29:01.797Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "mozilla",
    "firefox",
    "thunderbird",
    "tor",
    "use-after-free",
    "kev"
  ]
}
