CVE-2016-9480
9.1
CRITICAL · CVSS 3.0 · EPSS 3.6% (pctl 89)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.
Scoring
| CVSS | 9.1 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 3.64% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-11-29 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| libdwarf project | libdwarf |
References
- http://www.securityfocus.com/bid/94980
- https://sourceforge.net/p/libdwarf/bugs/5/
- https://sourceforge.net/p/libdwarf/code/ci/5dd64de047cd5ec479fb11fe7ff2692fd819e5e5/
- https://www.prevanders.net/dwarfbug.html
- http://www.securityfocus.com/bid/94980
- https://sourceforge.net/p/libdwarf/bugs/5/
- https://sourceforge.net/p/libdwarf/code/ci/5dd64de047cd5ec479fb11fe7ff2692fd819e5e5/
- https://www.prevanders.net/dwarfbug.html
→ the Explorer · watch your stack · NVD