cbcvebase.
CVE-2016-9840
published 2017-05-23

CVE-2016-9840: inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

PriorityP342high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.79%
91.0th percentile
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
appleios
appleiphone_os< 1111
applemac_os_x>= 10.0.0 < 10.13.010.13.0
applemacos_high_sierra
appletvos< 11.011.0
appletvos
applewatchos< 44
applewatchos_4
boostboost< 1.78.01.78.0
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianrsync< rsync 3.1.3-6 (bookworm)rsync 3.1.3-6 (bookworm)
debianzlib< rsync 3.1.3-6 (bookworm)rsync 3.1.3-6 (bookworm)
klibc_projectklibc>= 0 < 2.0.7-1ubuntu5.22.0.7-1ubuntu5.2
klibc_projectklibc>= 0 < 2.0.10-4ubuntu0.12.0.10-4ubuntu0.1
klibc_projectklibc>= 0 < 2.0.13-4ubuntu0.12.0.13-4ubuntu0.1
klibc_projectklibc>= 0 < 2.0.3-0ubuntu1.14.04.3+esm32.0.3-0ubuntu1.14.04.3+esm3
klibc_projectklibc>= 0 < 2.0.4-8ubuntu1.16.04.4+esm22.0.4-8ubuntu1.16.04.4+esm2
klibc_projectklibc>= 0 < 2.0.4-9ubuntu2.2+esm12.0.4-9ubuntu2.2+esm1
msrcazl3_fltk_1.3.8-1_on_azure_linux_3.0
msrcazl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0
msrccbl2_boost_1.76.0-4_on_cbl_mariner_2.0
nodejsnode.js4.0.0 – 4.1.2
nodejsnode.js>= 4.2.0 < 4.8.24.8.2

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.