Back

HIGH KEV

Mozilla: Firefox SVG Animation Remote Code Execution (MFSA 2016-92)

Published Jun 11, 2018 ·Due Jul 13, 2023

Description

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jun 11, 2018
Updated Oct 21, 2025
Reserved Oct 27, 2016
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Dec 1, 2016