CVE-2016-4658
Severity
9.8CRITICAL
EPSS
17.7%
top 4.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 25
Latest updateAug 21
Description
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages7 packages
Patches
🔴Vulnerability Details
5📋Vendor Advisories
8Android▶
CVE-2016-4658: Android Security Bulletin 2017-06-01
CVE: CVE-2016-4658
Severity: HIGH
Type: RCE
Affected AOSP versions: 4↗2017-06-01