8.8

CVE-2016-9842

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

Data is provided by the National Vulnerability Database (NVD)
ZlibZlib Version >= 1.2.3.4 < 1.2.9
OpensuseLeap Version42.1
OpensuseLeap Version42.2
OpensuseOpensuse Version13.2
DebianDebian Linux Version8.0
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version18.04 SwEditionesm
OracleDatabase Server Version18c
OracleJdk Version1.6.0 Updateupdate161
OracleJdk Version1.7.0 Updateupdate151
OracleJdk Version1.8.0 Updateupdate144
OracleJre Version1.6.0 Updateupdate161
OracleJre Version1.7.0 Updateupdate151
OracleJre Version1.8.0 Updateupdate144
OracleMysql Version >= 5.5.0 <= 5.5.61
OracleMysql Version >= 5.6.0 <= 5.6.41
OracleMysql Version >= 5.7.0 <= 5.7.23
OracleMysql Version >= 8.0.0 <= 8.0.12
RedhatSatellite Version5.8
RedhatEnterprise Linux Eus Version7.4
RedhatEnterprise Linux Eus Version7.5
AppleiPhone OS Version < 11
ApplemacOS X Version >= 10.0.0 < 10.13.0
AppletvOS Version < 11.0
ApplewatchOS Version < 4
NodejsNode.Js SwEdition- Version >= 4.0.0 <= 4.1.2
NodejsNode.Js SwEditionlts Version >= 4.2.0 < 4.8.2
NodejsNode.Js SwEdition- Version >= 6.0.0 <= 6.8.1
NodejsNode.Js SwEditionlts Version >= 6.9.0 < 6.10.2
NodejsNode.Js SwEdition- Version >= 7.0.0 < 7.6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 10.91% 0.932
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
http://www.securitytracker.com/id/1039427
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/95131
Third Party Advisory
Broken Link
VDB Entry
https://usn.ubuntu.com/4246-1/
Third Party Advisory
https://usn.ubuntu.com/4292-1/
Third Party Advisory