cbcvebase.
CVE-2016-4608
published 2016-07-22

CVE-2016-4608: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-4609, CVE-2016-4610, and CVE-2016-4612.

Affected

24 ranges
VendorProductVersion rangeFixed in
appleicloud< 5.2.15.2.1
appleicloud_for_windows
appleios
appleiphone_os< 9.3.39.3.3
appleitunes< 12.4.212.4.2
appleitunes_12.4.2_for_windows
applemac_os_x< 10.11.610.11.6
appleos_x_el_capitan_v10.11.6_and_security_update_2016-004
appletvos< 9.2.29.2.2
appletvos
applewatchos< 2.2.22.2.2
applewatchos
debiandebian_linux
debianlibxslt< libxslt 1.1.29-1 (bookworm)libxslt 1.1.29-1 (bookworm)
fedoraprojectfedora
paloaltopan-os
xmlsoftlibxslt< 1.1.291.1.29
xmlsoftlibxslt<= 1.1.28
xmlsoftlibxslt>= 0 < 1.1.29-11.1.29-1
xmlsoftlibxslt>= 0 < 1.1.29-11.1.29-1
xmlsoftlibxslt>= 0 < 1.1.29-11.1.29-1
xmlsoftlibxslt>= 0 < 1.1.29-11.1.29-1
xmlsoftlibxslt>= 0 < 1.1.28-2ubuntu0.11.1.28-2ubuntu0.1
xmlsoftlibxslt>= 0 < 1.1.28-2.1ubuntu0.11.1.28-2.1ubuntu0.1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL