peter bassill · operator
$ cve CVE-2016-9841 JSON

CVE-2016-9841

9.8
CRITICAL · CVSS 3.1 · EPSS 7.6% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.55% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploitnone known
Published2017-05-23
Last modified2026-07-14

Affected (39)

VendorProduct
appleiphone os
applemac os x
appletvos
applewatchos
canonicalubuntu linux
debiandebian linux
netappactive iq unified manager
netappcloud backup
netappe-series santricity management
netappe-series santricity os controller
netappe-series santricity storage manager
netappe-series santricity web services
netapphci storage node
netapponcommand balance
netapponcommand insight
netapponcommand performance manager
netapponcommand shift
netapponcommand unified manager
netapponcommand workflow automation
netappsnapmanager
netappsolidfire
netappsteelstore cloud integrated storage
netappstorage replication adapter for clustered data ontap
netappsymantec netbackup
netappvasa provider for clustered data ontap
netappvirtual storage console
nodejsnode.js
opensuseleap
opensuseopensuse
oracledatabase server
oraclejdk
oraclejre
oraclemysql
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux workstation
redhatsatellite
zlibzlib

References

→ the Explorer  ·  watch your stack  ·  NVD