Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2016-9840

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

  • Published: May 23, 2017
  • Updated: Nov 8, 2023
  • CVE: CVE-2016-9840
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.8
  • AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

No CWE or OWASP classifications available.

Software From Fixed in
zlib / zlib 1.2.0.6 1.2.9
opensuse / leap 42.2 42.2.x
opensuse / leap 42.1 42.1.x
opensuse / opensuse 13.2 13.2.x
debian / debian_linux 8.0 8.0.x
canonical / ubuntu_linux 18.04 18.04.x
canonical / ubuntu_linux 16.04 16.04.x
oracle / mysql 5.7.0 5.7.23.x
oracle / mysql 8.0.0 8.0.12.x
oracle / mysql 5.5.0 5.5.61.x
oracle / mysql 5.6.0 5.6.41.x
oracle / database_server 18c 18c.x
oracle / jdk 1.8.0-update144 1.8.0-update144.x
oracle / jdk 1.7.0-update151 1.7.0-update151.x
oracle / jdk 1.6.0-update161 1.6.0-update161.x
oracle / jre 1.6.0-update161 1.6.0-update161.x
oracle / jre 1.8.0-update144 1.8.0-update144.x
oracle / jre 1.7.0-update151 1.7.0-update151.x
redhat / enterprise_linux_desktop 7.0 7.0.x
redhat / enterprise_linux_workstation 7.0 7.0.x
redhat / enterprise_linux_server 7.0 7.0.x
redhat / enterprise_linux_desktop 6.0 6.0.x
redhat / enterprise_linux_server 6.0 6.0.x
redhat / enterprise_linux_workstation 6.0 6.0.x
redhat / enterprise_linux_eus 7.4 7.4.x
redhat / enterprise_linux_eus 7.5 7.5.x
redhat / satellite 5.8 5.8.x
apple / tvos - 11.0
apple / iphone_os - 11
apple / watchos - 4
apple / mac_os_x 10.0.0 10.13.0
nodejs / node.js 4.0.0 4.1.2.x
nodejs / node.js 6.0.0 6.8.1.x
nodejs / node.js 4.2.0 4.8.2
nodejs / node.js 6.9.0 6.10.2
nodejs / node.js 7.0.0 7.6.0