CVE-2016-0718
published 2016-05-26CVE-2016-0718: Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
13.80%
96.1th percentile
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | itunes | — | — |
| apple | itunes_12.6_for_windows | — | — |
| apple | mac_os_x | 10.11.0 – 10.11.5 | — |
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.1.1-2 (bookworm) | expat 2.1.1-2 (bookworm) |
| debian | firefox | < expat 2.1.1-2 (bookworm) | expat 2.1.1-2 (bookworm) |
| debian | firefox-esr | < expat 2.1.1-2 (bookworm) | expat 2.1.1-2 (bookworm) |
| debian | libxmltok | < expat 2.1.1-2 (bookworm) | expat 2.1.1-2 (bookworm) |
| eset | endpoint_antivirus | — | — |
| eset | endpoint_security | — | — |
| android | — | — | |
| libexpat_project | libexpat | < 2.2.0 | 2.2.0 |
| mcafee | policy_auditor | < 6.5.1 | 6.5.1 |
| mozilla | firefox | < 48.0 | 48.0 |
| mozilla | firefox | >= 0 < 48.0+build2-0ubuntu0.14.04.1 | 48.0+build2-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 48.0+build2-0ubuntu0.16.04.1 | 48.0+build2-0ubuntu0.16.04.1 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| python | python | >= 2.7.0 < 2.7.15 | 2.7.15 |
| python | python | >= 3.3.0 < 3.3.7 | 3.3.7 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2025-01-13·CVSS 6.8
CVE-2019-15903 [MEDIUM] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
It was discovered that Expat, contained within the xmltok library,
incorrectly handled malformed XML data. If a user or application were
tricked into opening a crafted XML file, an attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2019-15903)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled XML data containing a large number of colons, which
could lead to excessive resource consumption. If a user or application
were tricked into opening a crafted XML file, an attacker could possibly
use this issue to cause a denial of service. (CVE-2018-20843)
It was discovered that Expat, cont
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2022-07-19·CVSS 5.0
CVE-2021-46143 [MEDIUM] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, o
Apple
CVE-2016-0718: iTunes 12.6
vendor_apple·2017-03-21·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2016-0718
Component: CVE-2016-0718
Apple
CVE-2016-0718: iTunes 12.6 for Windows
vendor_apple·2017-03-21·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718: iTunes 12.6 for Windows
Apple Security Update: About the security content of iTunes 12.6 for Windows
Product: iTunes 12.6 for Windows
CVE: CVE-2016-0718
Component: CVE-2016-0718
Android
CVE-2016-0718: Android Security Bulletin 2016-11-01
CVE: CVE-2016-0718
Severity: HIGH
Affected AOSP versions: 4
vendor_android·2016-11-01·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718: Android Security Bulletin 2016-11-01
CVE: CVE-2016-0718
Severity: HIGH
Affected AOSP versions: 4
Android Security Bulletin 2016-11-01
CVE: CVE-2016-0718
Severity: HIGH
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1
References: A-28698301
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2016-08-05·CVSS 9.8
CVE-2016-0718 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Gustavo Grieco discovered an out-of-bounds read during XML parsing in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to cause a
denial of service via application crash, or obtain sensitive information.
(CVE-2016-0718)
Toni Huttunen discovered that once a favicon is requested from a site,
the remote server can keep the network connection open even after the page
is closed. A remote attacked could potentially exploit this to track
users, resulting in information disclosure. (CVE-2016-2830)
Christian Holler, Tyson Smith, Boris Zbarsky, Byron Campen, Julian Seward,
Carsten Boo
Apple
CVE-2016-0718: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2016-0718
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
Ubuntu
XML-RPC for C and C++ vulnerabilities
vendor_ubuntu·2016-06-20·CVSS 5.9
CVE-2012-6702 [MEDIUM] XML-RPC for C and C++ vulnerabilities
Title: XML-RPC for C and C++ vulnerabilities
Summary: Several security issues were fixed in XML-RPC for C and C++.
It was discovered that the Expat code in XML-RPC for C and C++ unexpectedly
called srand in certain circumstances. This could reduce the security of
calling applications. (CVE-2012-6702)
It was discovered that the Expat code in XML-RPC for C and C++ incorrectly
handled seeding the random number generator. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2016-5300)
Gustavo Grieco discovered that the Expat code in XML-RPC for C and C++
incorrectly handled malformed XML data. If a user or application linked
against XML-RPC for C and C++ were tricked into opening a crafted XML file,
an attacker could cause a denial of service, or possibly exec
Ubuntu
Expat vulnerability
vendor_ubuntu·2016-05-18·CVSS 9.8
CVE-2016-0718 [CRITICAL] Expat vulnerability
Title: Expat vulnerability
Summary: Expat could be made to crash or run programs as your login if it opened a
specially crafted file.
Gustavo Grieco discovered that Expat incorrectly handled malformed XML
data. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service, or
possibly execute arbitrary code. (CVE-2016-0718)
Instructions: After a standard system upgrade you need to restart any applications linked
against Expat to effect the necessary changes.
Red Hat
expat: Out-of-bounds heap read on crafted input causing crash
vendor_redhat·2016-05-17·CVSS 9.8
CVE-2016-0718 [CRITICAL] CWE-125 expat: Out-of-bounds heap read on crafted input causing crash
expat: Out-of-bounds heap read on crafted input causing crash
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
An out-of-bounds read flaw was found in the way Expat processed certain input. A remote attacker could send specially crafted XML that, when parsed by an application using the Expat library, would cause that application to crash or, possibly, execute arbitrary code with the permission of the user running the application.
Package: expat (Red Hat Directory Server 8) - Under investigation
Package: expat (Red Hat Enterprise Linux 5) - Will not fix
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Lin
Debian
CVE-2016-0718: expat - Expat allows context-dependent attackers to cause a denial of service (crash) or...
vendor_debian·2016·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718: expat - Expat allows context-dependent attackers to cause a denial of service (crash) or...
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.1.1-2)
bullseye: resolved (fixed in 2.1.1-2)
forky: resolved (fixed in 2.1.1-2)
sid: resolved (fixed in 2.1.1-2)
trixie: resolved (fixed in 2.1.1-2)
OSV
libxmltok vulnerabilities
osv·2025-01-13·CVSS 6.8
CVE-2015-1283 [MEDIUM] libxmltok vulnerabilities
libxmltok vulnerabilities
It was discovered that Expat, contained within the xmltok library,
incorrectly handled malformed XML data. If a user or application were
tricked into opening a crafted XML file, an attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2019-15903)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled XML data containing a large number of colons, which
could lead to excessive resource consumption. If a user or application
were tricked into opening a crafted XML file, an attacker could possibly
use this issue to cause a denial of service. (CVE-2018-20843)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled certain input, whi
OSV
libxmltok vulnerabilities
osv·2022-07-19·CVSS 5.0
CVE-2012-1148 [MEDIUM] libxmltok vulnerabilities
libxmltok vulnerabilities
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2022-25235)
It was discovered
GHSA
GHSA-3cqj-j486-jhq2: The esets_daemon service in ESET Endpoint Antivirus for macOS before 6
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-9892 [CRITICAL] CWE-295 GHSA-3cqj-j486-jhq2: The esets_daemon service in ESET Endpoint Antivirus for macOS before 6
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide crafted responses to license activation requests via a self-signed certificate. NOTE: this issue can be combined with CVE-2016-0718 to execute arbitrary code remotely as root.
GHSA
GHSA-3f8j-8ww3-q7v6: Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which
ghsa_unreviewed·2022-05-13
CVE-2016-0718 [CRITICAL] CWE-119 GHSA-3f8j-8ww3-q7v6: Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
OSV
firefox vulnerabilities
osv·2016-08-05·CVSS 9.8
CVE-2016-0718 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Gustavo Grieco discovered an out-of-bounds read during XML parsing in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to cause a
denial of service via application crash, or obtain sensitive information.
(CVE-2016-0718)
Toni Huttunen discovered that once a favicon is requested from a site,
the remote server can keep the network connection open even after the page
is closed. A remote attacked could potentially exploit this to track
users, resulting in information disclosure. (CVE-2016-2830)
Christian Holler, Tyson Smith, Boris Zbarsky, Byron Campen, Julian Seward,
Carsten Book, Gary Kwong, Jesse Ruderman, Andrew McCreight, and Phil
Ringnalda discovered multiple memory safety issues in
OSV
CVE-2016-0718: Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which
osv·2016-05-26·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718: Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
OSV
expat vulnerability
osv·2016-05-18·CVSS 9.8
CVE-2016-0718 [CRITICAL] expat vulnerability
expat vulnerability
Gustavo Grieco discovered that Expat incorrectly handled malformed XML
data. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service, or
possibly execute arbitrary code. (CVE-2016-0718)
No detection rules found.
No public exploits indexed.
Bugzilla
Update to Expat 2.2.1
bugzilla·2017-06-18·CVSS 4.3
[MEDIUM] Update to Expat 2.2.1
Update to Expat 2.2.1
Update expat files that live in: parser/expat/lib/
For list of fixed CVEs see:
http://www.openwall.com/lists/oss-security/2017/06/17/7
Discussion:
This fixes some integer overflows, a double free and more. So marking s-s for now.
---
FWIW I've explicitly avoided updating to the latest expat versions as they've tend to introduce more CVE's than they fix. We keep a much trimmed down (and modified) version of 2.0.0 in tree, it would be interesting to see what overlap there is and maybe just cherry-pick changes that are relevant to us.
---
I've started looking over the differences. I'll attach some patches with some no-brainers and then we can decide on the rest.
---
From the release notes:
CVE-2017-9233 External entity infinite loop DoS
Probably affects us, I
Bugzilla
CVE-2016-0718 mingw-expat: expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]
bugzilla·2016-05-18·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718 mingw-expat: expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]
CVE-2016-0718 mingw-expat: expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2016-0718 expat21: expat: Out-of-bounds heap read on crafted input causing crash [epel-all]
bugzilla·2016-05-18·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718 expat21: expat: Out-of-bounds heap read on crafted input causing crash [epel-all]
CVE-2016-0718 expat21: expat: Out-of-bounds heap read on crafted input causing crash [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2016-0718 mingw-expat: expat: Out-of-bounds heap read on crafted input causing crash [epel-all]
bugzilla·2016-05-18·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718 mingw-expat: expat: Out-of-bounds heap read on crafted input causing crash [epel-all]
CVE-2016-0718 mingw-expat: expat: Out-of-bounds heap read on crafted input causing crash [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2016-0718 compat-expat1: expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]
bugzilla·2016-05-18·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718 compat-expat1: expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]
CVE-2016-0718 compat-expat1: expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2016-0718 expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]
bugzilla·2016-05-18·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718 expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]
CVE-2016-0718 expat: Out-of-bounds heap read on crafted input causing crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2016-0718 expat: Out-of-bounds heap read on crafted input causing crash
bugzilla·2016-01-06·CVSS 9.8
CVE-2016-0718 [CRITICAL] CVE-2016-0718 expat: Out-of-bounds heap read on crafted input causing crash
CVE-2016-0718 expat: Out-of-bounds heap read on crafted input causing crash
The Expat XML parser mishandles certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. The overflows can manifest as a segmentation fault or as memory corruption during a parse operation. The bugs allow for a denial of service attack in many applications by an unauthenticated attacker, and could conceivably result in remote code execution.
Discussion:
Acknowledgments:
Name: Gustavo Grieco
---
Thank you very much for your excellent work!
Sorry, I should really have seen your comments earlier but I haven't - a misunderstanding between me and my email filtering.
Indeed, python is problematic here. Does python upstream have a release date yet? I'll whip
Bugzilla
Heap read out-of-bound and crash in expat 2.1.0
bugzilla·2016-01-05
[MEDIUM] Heap read out-of-bound and crash in expat 2.1.0
Heap read out-of-bound and crash in expat 2.1.0
Created attachment 8704150
overflow.xml
User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:43.0) Gecko/20100101 Firefox/43.0
Build ID: 20151210085006
Steps to reproduce:
A read out-of-bound in the heap was detected in expat 2.1.0 (tested in Ubuntu 14.04). There is no crash in Firefox opening the xml, but I don't know if this affect the expat code in the Mozilla repositories anyway.
Actual results:
$ xmlwf overflow.xml
==16291== ERROR: AddressSanitizer: heap-buffer-overflow on address 0xb5a03e80 at pc 0x81021d0 bp 0xbfffeb48 sp 0xbfffeb3c
READ of size 1 at 0xb5a03e80 thread T0
#0 0x81021cf (/home/vagrant/afl-tests/progs/expat-2.1.0/xmlwf/xmlwf+0x81021cf)
#1 0x8068791 (/home/vagrant/afl-tests/progs/expat-2.1.0/xmlwf/xmlwf+0x8068791)
Tenable
[R5] Nessus 6.8 Fixes Multiple Vulnerabilities
blogs_tenable·2016-07-13
[R5] Nessus 6.8 Fixes Multiple Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00029.htmlhttp://packetstormsecurity.com/files/141350/ESET-Endpoint-Antivirus-6-Remote-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2824.htmlhttp://seclists.org/fulldisclosure/2017/Feb/68http://support.eset.com/ca6333/http://www.debian.org/security/2016/dsa-3582http://www.mozilla.org/security/announce/2016/mfsa2016-68.htmlhttp://www.openwall.com/lists/oss-security/2016/05/17/12http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/90729http://www.securitytracker.com/id/1036348http://www.securitytracker.com/id/1036415http://www.securitytracker.com/id/1037705http://www.ubuntu.com/usn/USN-2983-1http://www.ubuntu.com/usn/USN-3044-1https://access.redhat.com/errata/RHSA-2018:2486https://bugzilla.mozilla.org/show_bug.cgi?id=1236923https://bugzilla.redhat.com/show_bug.cgi?id=1296102https://kc.mcafee.com/corporate/index?page=content&id=SB10365https://security.gentoo.org/glsa/201701-21https://source.android.com/security/bulletin/2016-11-01.htmlhttps://support.apple.com/HT206903https://www.tenable.com/security/tns-2016-20http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00029.htmlhttp://packetstormsecurity.com/files/141350/ESET-Endpoint-Antivirus-6-Remote-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2824.htmlhttp://seclists.org/fulldisclosure/2017/Feb/68http://support.eset.com/ca6333/http://www.debian.org/security/2016/dsa-3582http://www.mozilla.org/security/announce/2016/mfsa2016-68.htmlhttp://www.openwall.com/lists/oss-security/2016/05/17/12http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/90729http://www.securitytracker.com/id/1036348http://www.securitytracker.com/id/1036415http://www.securitytracker.com/id/1037705http://www.ubuntu.com/usn/USN-2983-1http://www.ubuntu.com/usn/USN-3044-1https://access.redhat.com/errata/RHSA-2018:2486https://bugzilla.mozilla.org/show_bug.cgi?id=1236923https://bugzilla.redhat.com/show_bug.cgi?id=1296102https://kc.mcafee.com/corporate/index?page=content&id=SB10365https://security.gentoo.org/glsa/201701-21https://source.android.com/security/bulletin/2016-11-01.htmlhttps://support.apple.com/HT206903https://www.tenable.com/security/tns-2016-20
2016-05-26
Published