CVE-2016-0718

Severity
9.8CRITICAL
EPSS
2.8%
top 13.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26
Latest updateJan 13

Description

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages16 packages

Debianexpat< 2.1.1-2+3
Ubuntuexpat< 2.1.0-4ubuntu1.2+1
NVDpython/python2.7.02.7.15+4
NVDmozilla/firefox< 48.0

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 16.04

Patches

🔴Vulnerability Details

7
OSV
libxmltok vulnerabilities2025-01-13
OSV
libxmltok vulnerabilities2022-07-19
GHSA
GHSA-3f8j-8ww3-q7v6: Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which2022-05-13
OSV
firefox vulnerabilities2016-08-05
CVEList
CVE-2016-0718: Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which2016-05-26

📋Vendor Advisories

11
Ubuntu
xmltok library vulnerabilities2025-01-13
Ubuntu
xmltok library vulnerabilities2022-07-19
Apple
CVE-2016-0718: iTunes 12.62017-03-21
Apple
CVE-2016-0718: iTunes 12.6 for Windows2017-03-21
Android
CVE-2016-0718: Android Security Bulletin 2016-11-01 CVE: CVE-2016-0718 Severity: HIGH Affected AOSP versions: 42016-11-01

💬Community

6
Bugzilla
CVE-2016-0718 mingw-expat: expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]2016-05-18
Bugzilla
CVE-2016-0718 expat21: expat: Out-of-bounds heap read on crafted input causing crash [epel-all]2016-05-18
Bugzilla
CVE-2016-0718 mingw-expat: expat: Out-of-bounds heap read on crafted input causing crash [epel-all]2016-05-18
Bugzilla
CVE-2016-0718 compat-expat1: expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]2016-05-18
Bugzilla
CVE-2016-0718 expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]2016-05-18