Back
CVE-2016-4448
CRITICAL
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Published: Jun 9, 2016
Modified: Jun 17, 2026
CWE-134
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (38)
| Vendor | Product | Version |
|---|---|---|
| hp | icewall_federation_agent | 3.0 |
| apple | watchos | * |
| apple | mac_os_x | * < 10.11.6 |
| xmlsoft | libxml2 | * |
| apple | icloud | * < 5.2.1 |
| apple | iphone_os | * |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.2 |
| redhat | enterprise_linux_server_aus | 7.3 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_aus | 7.6 |
| redhat | enterprise_linux_server_aus | 7.7 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_server_eus | 7.4 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_eus | 7.6 |
…and 18 more
GitHub Security Advisory GHSA-wfj9-g4pj-c38g
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact...
References (54)
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.html Mailing List, Release Notes
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.html Mailing List, Release Notes
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00002.html Mailing List, Release Notes
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00003.html Mailing List, Release Notes
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00005.html Mailing List, Release Notes
- http://rhn.redhat.com/errata/RHSA-2016-2957.html Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/05/25/2 Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html Vendor Advisory
- http://www.securityfocus.com/bid/90856 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036348 Third Party Advisory, VDB Entry
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.404722 Third Party Advisory
- http://xmlsoft.org/news.html Release Notes
- https://access.redhat.com/errata/RHSA-2016:1292 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
7.04%
Top 6% most likely to be exploited
Threat Score
41.3 / 100
Data Sources
NVD
EPSS
GitHub