Back

CVE-2016-9063

CRITICAL

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

Published: Jun 11, 2018 Modified: Jun 17, 2026
CWE-190

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (9)

Vendor Product Version
mozilla firefox * < 50
debian debian_linux 8.0
debian debian_linux 9.0
debian debian_linux 10.0
python python * ≥ 2.7.0 < 2.7.15
python python * ≥ 3.3.0 < 3.3.7
python python * ≥ 3.4.0 < 3.4.7
python python * ≥ 3.5.0 < 3.5.4
python python * ≥ 3.6.0 < 3.6.2

GitHub Security Advisory GHSA-v3g4-2m5p-cjh4

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.47%

Top 8% most likely to be exploited

Threat Score 40.8 / 100

Data Sources

NVD EPSS GitHub