CVE-2016-9584 β Use After Free in Project Libical
Severity
9.1CRITICALNVD
EPSS
0.8%
top 26.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 18
Latest updateMay 17
Description
libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2
Affected Packages1 packages
π΄Vulnerability Details
3GHSAβΆ
GHSA-hcxq-m379-hxr9: libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics fileβ2022-05-17
CVEListβΆ
CVE-2016-9584: libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics fileβ2017-01-18
OSVβΆ
CVE-2016-9584: libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics fileβ2017-01-18
πVendor Advisories
2π¬Community
5BugzillaβΆ
CVE-2016-5825 CVE-2016-5826 CVE-2016-5827 libical: Multiple heap over-read vulnerabilities [fedora-all]β2016-06-27