peter bassill · operator
$ cve CVE-2016-6855 JSON

CVE-2016-6855 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 18.9% (pctl 97)

Patch early

A public exploit exists.

Description

Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS18.86% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploityes
Published2016-09-07
Last modified2026-06-17

Affected (6)

VendorProduct
canonicalubuntu linux
fedoraprojectfedora
gnomeeye of gnome
gnomeglib
opensuseleap
opensuseopensuse

Public exploits

SourceTitleDate
exploit-dbEye of Gnome 3.10.2 - GMarkup Out of Bounds Write2016-08-23

References

→ the Explorer  ·  watch your stack  ·  NVD