CVE-2016-9841
CRITICALzlib <1.2.8 - Info Disclosure
Title source: llmDescription
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
References (33)
Scores
CVSS v3
9.8
EPSS
0.2028
EPSS Percentile
95.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
Status
draft
Affected Products (50)
zlib/zlib
< 1.2.9
opensuse/leap
opensuse/leap
opensuse/opensuse
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
oracle/database_server
oracle/jdk
oracle/jdk
oracle/jdk
oracle/jre
oracle/jre
oracle/jre
oracle/mysql
< 5.5.61
... and 35 more
Timeline
Published
May 23, 2017
Tracked Since
Feb 18, 2026