peter bassill · operator
$ cve CVE-2016-4448 JSON

CVE-2016-4448

9.8
CRITICAL · CVSS 3.1 · EPSS 7% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.04% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-134
On CISA KEVno
Public exploitnone known
Published2016-06-09
Last modified2026-06-17

Affected (21)

VendorProduct
appleicloud
appleiphone os
appleitunes
applemac os x
appletvos
applewatchos
hpicewall federation agent
mcafeeweb gateway
microsoftwindows
oraclelinux
oraclevm server
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
slackwareslackware linux
tenablelog correlation engine
xmlsoftlibxml2

References

→ the Explorer  ·  watch your stack  ·  NVD