CVE-2016-4448

CRITICAL

HP Icewall Federation Agent < 2.2.1 - Format String Vulnerability

Title source: rule
STIX 2.1

Description

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

References (27)

Core 27
Core References
Third Party Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10170
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2016:1292
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/05/25/2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/90856
Mailing List, Release Notes vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Jul/msg00003.html
Mailing List, Release Notes vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Jul/msg00002.html
Mailing List, Release Notes vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.html
Release Notes x_refsource_confirm
http://xmlsoft.org/news.html
Release Notes x_refsource_confirm
https://support.apple.com/HT206901
Mailing List, Release Notes vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.html
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1338700
Mailing List, Release Notes vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Jul/msg00005.html
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2016-18
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2957.html
Release Notes x_refsource_confirm
https://support.apple.com/HT206905
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036348
Release Notes x_refsource_confirm
https://support.apple.com/HT206903
Release Notes x_refsource_confirm
https://support.apple.com/HT206902
Release Notes x_refsource_confirm
https://support.apple.com/HT206904
Release Notes x_refsource_confirm
https://support.apple.com/HT206899

Scores

CVSS v3 9.8
EPSS 0.0704
EPSS Percentile 93.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-134
Status published
Products (37)
apple/icloud < 5.2.1
apple/iphone_os < 9.3.2
apple/itunes < 12.4.1
apple/mac_os_x < 10.11.6
apple/tvos < 9.2.1
apple/watchos < 2.2.1
hp/icewall_federation_agent 3.0
mcafee/web_gateway < 7.5.2.10
oracle/linux 6
oracle/linux 7 0
... and 27 more
Published Jun 09, 2016
Tracked Since Feb 18, 2026