CVE-2016-1839
published 2016-05-20CVE-2016-1839: The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1…
medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EXPLOIT
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 9.3.2 | 9.3.2 |
| apple | mac_os_x | < 10.11.5 | 10.11.5 |
| apple | os_x_el_capitan_v10.11.5_and_security_update_2016-003 | — | — |
| apple | tvos | < 9.2.1 | 9.2.1 |
| apple | tvos | — | — |
| apple | watchos | < 2.2.1 | 2.2.1 |
| apple | watchos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.3+dfsg1-1.1 (bookworm) | libxml2 2.9.3+dfsg1-1.1 (bookworm) |
| debian | libxml2 | < libxml2 2.9.4+dfsg1-3.1 (bookworm) | libxml2 2.9.4+dfsg1-3.1 (bookworm) |
| android | — | — | |
| mcafee | web_gateway | 7.5.0.0 – 7.5.2.10 | — |
| mcafee | web_gateway | 7.6.0.0 – 7.6.2.3 | — |
| nokogiri | nokogiri | >= 0 < 1.8.1 | 1.8.1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
ghsa5.5MEDIUM
osv7.5HIGH
GHSA
GHSA-768p-297v-97cm: The xmlDictAddString function in libxml2 before 2
ghsa_unreviewed·2022-05-14
CVE-2016-1839 [MEDIUM] CWE-125 GHSA-768p-297v-97cm: The xmlDictAddString function in libxml2 before 2
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
OSV
Out-of-bounds read in nokogiri
osv·2017-12-13·CVSS 5.5
CVE-2017-9050 [MEDIUM] Out-of-bounds read in nokogiri
Out-of-bounds read in nokogiri
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839. GitHub is notifying on nokogiri as uses libxml2.
GHSA
Out-of-bounds read in nokogiri
ghsa·2017-12-13·CVSS 5.5
CVE-2017-9050 [MEDIUM] CWE-125 Out-of-bounds read in nokogiri
Out-of-bounds read in nokogiri
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839. GitHub is notifying on nokogiri as uses libxml2.
OSV
CVE-2017-9050: libxml2 20904-GITv2
osv·2017-05-18·CVSS 5.5
CVE-2017-9050 [MEDIUM] CVE-2017-9050: libxml2 20904-GITv2
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.
OSV
libxml2 vulnerabilities
osv·2016-06-06·CVSS 7.5
CVE-2015-8806 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could possibly cause libxml2 to
crash, resulting in a denial of service. (CVE-2015-8806, CVE-2016-2073,
CVE-2016-3627, CVE-2016-3705, CVE-2016-4447)
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-1762, CVE-2016-1834)
Mateusz Jurczyk discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
OSV
CVE-2016-1839: The xmlDictAddString function in libxml2 before 2
osv·2016-05-20·CVSS 5.5
CVE-2016-1839 [MEDIUM] CVE-2016-1839: The xmlDictAddString function in libxml2 before 2
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Android
CVE-2016-1839: Android Security Bulletin 2017-06-01
CVE: CVE-2016-1839
Severity: MEDIUM
Type: DoS
Affected AOSP versions: 4
vendor_android·2017-06-01·CVSS 5.5
CVE-2016-1839 [MEDIUM] CVE-2016-1839: Android Security Bulletin 2017-06-01
CVE: CVE-2016-1839
Severity: MEDIUM
Type: DoS
Affected AOSP versions: 4
Android Security Bulletin 2017-06-01
CVE: CVE-2016-1839
Severity: MEDIUM
Type: DoS
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2
References: A-36553781
Red Hat
libxml2: Heap-based buffer over-read in function xmlDictAddString
vendor_redhat·2017-05-15·CVSS 5.5
CVE-2017-9050 [MEDIUM] CWE-125 libxml2: Heap-based buffer over-read in function xmlDictAddString
libxml2: Heap-based buffer over-read in function xmlDictAddString
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: libxml2 (Red Hat Enterprise Linux 6) - Will not fix
Package: libxml2 (Red Hat Enterprise Linux 7) - Will not fix
Package: libxml2 (Red Hat Enterprise Linux 8) - Not affected
Package: mingw-libxml2 (Red Hat Enterprise Linux 8) - Affected
Package: libxml2 (Red Hat JBoss Core Services) - Affected
Package: libxml2 (Red Hat JBoss Enterprise Web Server 3) - Will not fix
Debian
CVE-2017-9050: libxml2 - libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-re...
vendor_debian·2017·CVSS 5.5
CVE-2017-9050 [MEDIUM] CVE-2017-9050: libxml2 - libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-re...
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.
Scope: local
bookworm: resolved (fixed in 2.9.4+dfsg1-3.1)
bullseye: resolved (fixed in 2.9.4+dfsg1-3.1)
forky: resolved (fixed in 2.9.4+dfsg1-3.1)
sid: resolved (fixed in 2.9.4+dfsg1-3.1)
trixie: resolved (fixed in 2.9.4+dfsg1-3.1)
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2016-06-06·CVSS 7.5
CVE-2015-8806 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could possibly cause libxml2 to
crash, resulting in a denial of service. (CVE-2015-8806, CVE-2016-2073,
CVE-2016-3627, CVE-2016-3705, CVE-2016-4447)
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-1762, CVE-2016-1834)
Mateusz Jurczyk discovered that libxml2 incorrectly handled certain
malfo
Red Hat
libxml2: Heap-based buffer overread in xmlDictAddString
vendor_redhat·2016-05-23·CVSS 5.5
CVE-2016-1839 [MEDIUM] CWE-122 libxml2: Heap-based buffer overread in xmlDictAddString
libxml2: Heap-based buffer overread in xmlDictAddString
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: libxml2 (Red Hat JBoss Enterprise Web Server 3) - Affected
Red Hat
libxml2: heap-buffer overread in dict.c
vendor_redhat·2016-01-26·CVSS 7.5
CVE-2015-8806 [HIGH] CWE-122 libxml2: heap-buffer overread in dict.c
libxml2: heap-buffer overread in dict.c
dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.
Statement: This flaw was found to be a duplicate of CVE-2016-1839. Please see https://access.redhat.com/security/cve/CVE-2016-1839 for information about affected products and security errata.
Package: libxml2 (Red Hat Enterprise Linux 5) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 6) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 7) - Not affected
Red Hat
libxml2: out-of-bounds read in htmlParseNameComplex()
vendor_redhat·2016-01-25·CVSS 5.5
CVE-2016-2073 [MEDIUM] CWE-20 libxml2: out-of-bounds read in htmlParseNameComplex()
libxml2: out-of-bounds read in htmlParseNameComplex()
The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.
Statement: This flaw was found to be a duplicate of CVE-2016-1839. Please see https://access.redhat.com/security/cve/CVE-2016-1839 for information about affected products and security errata.
Package: libxml2 (Red Hat Enterprise Linux 5) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 6) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-1839: libxml2 - The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS befo...
vendor_debian·2016·CVSS 5.5
CVE-2016-1839 [MEDIUM] CVE-2016-1839: libxml2 - The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS befo...
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1.1)
bullseye: resolved (fixed in 2.9.3+dfsg1-1.1)
forky: resolved (fixed in 2.9.3+dfsg1-1.1)
sid: resolved (fixed in 2.9.3+dfsg1-1.1)
trixie: resolved (fixed in 2.9.3+dfsg1-1.1)
Apple
CVE-2016-1839: iOS 9.3.2
vendor_apple·CVSS 5.5
CVE-2016-1839 [MEDIUM] CVE-2016-1839: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1839
Component: CVE-ID
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
Apple
CVE-2016-1839: watchOS 2.2.1
vendor_apple·CVSS 5.5
CVE-2016-1839 [MEDIUM] CVE-2016-1839: watchOS 2.2.1
Apple Security Update: About the security content of watchOS 2.2.1
Product: watchOS
Version: 2.2.1
CVE: CVE-2016-1839
Component: CVE-ID
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
Apple
CVE-2016-1839: tvOS 9.2.1
vendor_apple·CVSS 5.5
CVE-2016-1839 [MEDIUM] CVE-2016-1839: tvOS 9.2.1
Apple Security Update: About the security content of tvOS 9.2.1
Product: tvOS
Version: 9.2.1
CVE: CVE-2016-1839
Component: CVE-ID
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
Apple
CVE-2016-1839: OS X El Capitan v10.11.5 and Security Update 2016-003
vendor_apple·CVSS 5.5
CVE-2016-1839 [MEDIUM] CVE-2016-1839: OS X El Capitan v10.11.5 and Security Update 2016-003
Apple Security Update: About the security content of OS X El Capitan v10.11.5 and Security Update 2016-003
Product: OS X El Capitan v10.11.5 and Security Update 2016-003
CVE: CVE-2016-1839
Component: CVE-ID
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
No detection rules found.
Bugzilla
CVE-2017-9050 libxml2: Heap-based buffer over-read in function xmlDictAddString
bugzilla·2017-05-19·CVSS 5.5
CVE-2017-9050 [MEDIUM] CVE-2017-9050 libxml2: Heap-based buffer over-read in function xmlDictAddString
CVE-2017-9050 libxml2: Heap-based buffer over-read in function xmlDictAddString
libxml2 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2 to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.
References:
http://seclists.org/oss-sec/2017/q2/258
Discussion:
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1452550]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1452551]
---
Upstream patch:
https://gitlab.gnome.org/GNOME/libxml2/commit/45752d2c3
Bugzilla
CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 libxml2: various flaws [fedora-a
bugzilla·2016-06-24·CVSS 8.1
CVE-2016-1762 [HIGH] CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 libxml2: various flaws [fedora-a
CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 libxml2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE
Bugzilla
CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 mingw-libxml2: various flaws [fe
bugzilla·2016-06-24·CVSS 8.1
CVE-2016-1762 [HIGH] CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 mingw-libxml2: various flaws [fe
CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 mingw-libxml2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention t
Bugzilla
CVE-2016-1839 libxml2: Heap-based buffer overread in xmlDictAddString
bugzilla·2016-05-23·CVSS 5.5
CVE-2016-1839 [MEDIUM] CVE-2016-1839 libxml2: Heap-based buffer overread in xmlDictAddString
CVE-2016-1839 libxml2: Heap-based buffer overread in xmlDictAddString
A vulnerability was found in the libxml2 library. A heap-based buffer overread could happen in xmlDictAddString.
References:
https://bugzilla.gnome.org/show_bug.cgi?id=758605
Upstream fix:
https://git.gnome.org/browse/libxml2/commit/?id=a820dbeac29d330bae4be05d9ecd939ad6b4aa33
Discussion:
*** Bug 1304636 has been marked as a duplicate of this bug. ***
---
*** Bug 1301928 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:1292 https://access.redhat.com/errata/RHSA-2016:1292
---
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1349794]
---
Created mingw-libxml
Bugzilla
CVE-2015-8806 libxml2: heap-buffer overread in dict.c
bugzilla·2016-02-04·CVSS 7.5
CVE-2015-8806 [HIGH] CVE-2015-8806 libxml2: heap-buffer overread in dict.c
CVE-2015-8806 libxml2: heap-buffer overread in dict.c
A heap-buffer overread vulnerability was found in libxml2. A specially crafted file can cause the application to crash.
External bugzilla report with reproducer:
https://bugzilla.gnome.org/show_bug.cgi?id=749115
CVE assignment:
http://seclists.org/oss-sec/2016/q1/277
Discussion:
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1304638]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1304639]
Affects: epel-7 [bug 1304640]
---
I believe that this is actually a duplicate of CVE-2016-2073
---
Actually marking this duplicate of CVE-2016-1839, to follow upstream.
*** This bug has been marked as a duplicate of bug 1338703 ***
---
Statement:
This flaw was found to be a du
Bugzilla
CVE-2016-2073 libxml2: out-of-bounds read in htmlParseNameComplex()
bugzilla·2016-01-26·CVSS 6.5
CVE-2016-2073 [MEDIUM] CVE-2016-2073 libxml2: out-of-bounds read in htmlParseNameComplex()
CVE-2016-2073 libxml2: out-of-bounds read in htmlParseNameComplex()
An out-of-bounds read flaw was reported in libxml2's htmlParseNameComplex() function:
http://seclists.org/oss-sec/2016/q1/199
A remote attacker could provide a specially crafted XML file that, when processed by an application linked against libxml2, could cause the application to disclose crash.
Discussion:
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1301929]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1301930]
Affects: epel-7 [bug 1301931]
---
Below is my current understanding of this issue (which, I believe, is identical to 1304636) :
The issue is when a word starts with normal ASCII chars and jumps to UTF multibytes chars.
The issue is in html
Tenable
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-02-01
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-01-31
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.apple.com/archives/security-announce/2016/May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/90691http://www.securitytracker.com/id/1035890http://www.securitytracker.com/id/1038623http://www.ubuntu.com/usn/USN-2994-1http://xmlsoft.org/news.htmlhttps://access.redhat.com/errata/RHSA-2016:1292https://bugzilla.gnome.org/show_bug.cgi?id=758605https://git.gnome.org/browse/libxml2/commit/?id=a820dbeac29d330bae4be05d9ecd939ad6b4aa33https://kc.mcafee.com/corporate/index?page=content&id=SB10170https://security.gentoo.org/glsa/201701-37https://support.apple.com/HT206564https://support.apple.com/HT206566https://support.apple.com/HT206567https://support.apple.com/HT206568https://www.debian.org/security/2016/dsa-3593https://www.tenable.com/security/tns-2016-18http://lists.apple.com/archives/security-announce/2016/May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/90691http://www.securitytracker.com/id/1035890http://www.securitytracker.com/id/1038623http://www.ubuntu.com/usn/USN-2994-1http://xmlsoft.org/news.htmlhttps://access.redhat.com/errata/RHSA-2016:1292https://bugzilla.gnome.org/show_bug.cgi?id=758605https://git.gnome.org/browse/libxml2/commit/?id=a820dbeac29d330bae4be05d9ecd939ad6b4aa33https://kc.mcafee.com/corporate/index?page=content&id=SB10170https://security.gentoo.org/glsa/201701-37https://support.apple.com/HT206564https://support.apple.com/HT206566https://support.apple.com/HT206567https://support.apple.com/HT206568https://www.debian.org/security/2016/dsa-3593https://www.tenable.com/security/tns-2016-18
2016-05-20
Published