CVE-2016-4448
published 2016-06-09CVE-2016-4448: Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 5.2.1 | 5.2.1 |
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | iphone_os | <= 9.3.2 | — |
| apple | itunes | <= 12.4.1 | — |
| apple | itunes_12.4.2_for_windows | — | — |
| apple | mac_os_x | < 10.11.6 | 10.11.6 |
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
| apple | tvos | <= 9.2.1 | — |
| apple | tvos | — | — |
| apple | watchos | <= 2.2.1 | — |
| apple | watchos | — | — |
| debian | libxml2 | < libxml2 2.9.4+dfsg1-1 (bookworm) | libxml2 2.9.4+dfsg1-1 (bookworm) |
| hp | icewall_federation_agent | — | — |
| mcafee | web_gateway | <= 7.5.2.10 | — |
| mcafee | web_gateway | 7.6.0.0 – 7.6.2.3 | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| oracle | vm_server | — | — |
| oracle | vm_server | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL