Back

CVE-2016-5281

CRITICAL

Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document.

Published: Sep 22, 2016 Modified: Jun 17, 2026
CWE-416

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (7)

Vendor Product Version
mozilla firefox *
mozilla firefox 45.0
mozilla firefox 45.0.1
mozilla firefox 45.0.2
mozilla firefox 45.1.1
mozilla firefox 45.2.0
mozilla firefox 45.3.0

GitHub Security Advisory GHSA-465v-39xq-8c56

Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.04%

Top 9% most likely to be exploited

Threat Score 40.7 / 100

Data Sources

NVD EPSS GitHub