CVE-2016-9079 is a use-after-free vulnerability in Mozilla's SVG animation implementation, involving the nsSMILTimeContainer object. Improper lifetime handling of the object can leave a stale reference available for subsequent use. It affects Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1. The flaw was exploited in the wild against Firefox and Tor Browser users on Windows.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Standalone browser exploit repository for CVE-2016-9079, a historical Firefox SMIL use-after-free leading to RCE. The repo is small and purpose-built: documentation files (README, SECURITY, CHANGELOG, docs/environment.md) plus two code files, index.html and worker.js. index.html is the browser entry point: it creates a Web Worker from /worker.js, builds crafted SVG/animate DOM objects in the SMIL namespace, performs heap spraying with ArrayBuffers, and triggers the bug by manipulating animation begin times before calling pauseAnimations() on an SVG container. worker.js contains the exploitation core: memory access helpers, PE parsing logic, gadget discovery, import resolution, ROP-chain construction, and shellcode staging/execution logic for Windows. The code resolves kernel32!VirtualAlloc and CreateThread, indicating active payload execution rather than mere crash/detection behavior. The exploit is not part of a framework in this repo; it is a standalone JavaScript port of a previously public Metasploit/Exploit-DB technique. It appears operational but narrowly targeted, with hardcoded assumptions about vulnerable Firefox/XUL layout and Windows environment, and no runtime fingerprinting or compatibility checks.
This repository contains a single Metasploit module targeting a use-after-free vulnerability (CVE-2016-9079) in Mozilla Firefox versions 38 to 41 on Windows. The exploit is delivered via a malicious web page, which serves both an HTML page and a JavaScript web worker to the victim's browser. The module leverages heap spraying and SVG/SMIL animation manipulation to trigger the vulnerability and execute arbitrary code. The payload is customizable and can be any Metasploit-supported Windows payload (e.g., reverse shell, meterpreter). The module is fully integrated into the Metasploit framework, weaponized for operational use, and requires the victim to visit the attacker's web server. The only endpoints exposed are the exploit HTML and the worker.js script, both served over HTTP by the Metasploit module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.