Back

CVE-2016-4448

CRITICAL

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

Published: Jun 9, 2016 Modified: Jun 17, 2026
CWE-134

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (38)

Vendor Product Version
hp icewall_federation_agent 3.0
apple watchos *
apple mac_os_x * < 10.11.6
xmlsoft libxml2 *
apple icloud * < 5.2.1
apple iphone_os *
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server 6.0
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_aus 7.2
redhat enterprise_linux_server_aus 7.3
redhat enterprise_linux_server_aus 7.4
redhat enterprise_linux_server_aus 7.6
redhat enterprise_linux_server_aus 7.7
redhat enterprise_linux_server_eus 7.2
redhat enterprise_linux_server_eus 7.3
redhat enterprise_linux_server_eus 7.4
redhat enterprise_linux_server_eus 7.5
redhat enterprise_linux_server_eus 7.6

…and 18 more

GitHub Security Advisory GHSA-wfj9-g4pj-c38g

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 7.04%

Top 6% most likely to be exploited

Threat Score 41.3 / 100

Data Sources

NVD EPSS GitHub