peter bassill · operator
$ cve CVE-2016-1839 JSON

CVE-2016-1839 EXPLOIT

5.5
MEDIUM · CVSS 3.0 · EPSS 7.3% (pctl 94)

Patch early

A public exploit exists.

Description

The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

Scoring

CVSS5.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS7.35% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-125
On CISA KEVno
Public exploityes
Published2016-05-20
Last modified2026-06-17

Affected (14)

VendorProduct
appleiphone os
applemac os x
appletvos
applewatchos
canonicalubuntu linux
debiandebian linux
mcafeeweb gateway
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
xmlsoftlibxml2

Public exploits

SourceTitleDate
exploit-dblibxml2 - xmlDictAddString Heap Buffer Overread2016-02-24

References

→ the Explorer  ·  watch your stack  ·  NVD