10

CVE-2016-4448

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

Data is provided by the National Vulnerability Database (NVD)
HpIcewall Federation Agent Version3.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
ApplewatchOS Version <= 2.2.1
ApplemacOS X Version < 10.11.6
XmlsoftLibxml2 Version <= 2.9.3
AppleiCloud Version < 5.2.1
   MicrosoftWindows Version-
AppleiPhone OS Version <= 9.3.2
AppleiTunes Version <= 12.4.1
   MicrosoftWindows
SlackwareSlackware Linux Version14.0
SlackwareSlackware Linux Version14.1
OracleVm Server Version3.3
OracleVm Server Version3.4
AppletvOS Version <= 9.2.1
TenableLog Correlation Engine Version4.8.0
McafeeWeb Gateway Version <= 7.5.2.10
McafeeWeb Gateway Version >= 7.6.0.0 <= 7.6.2.3
OracleLinux Version6
OracleLinux Version7 Update0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.2% 0.783
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

http://www.securitytracker.com/id/1036348
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/90856
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1338700
Third Party Advisory
Issue Tracking