CVE-2016-0718
criticalCVSS v3 Base Score
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.8%
Exploitation probability in 30 days
Top 14% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Vulnerability Report
Generated by CyberWatcher
Description
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
CWE
CWE-119Affected Products
mozilla firefoxapple mac os xsuse linux enterprise debuginfosuse studio onsitesuse linux enterprise serversuse linux enterprise software development kitopensuse leapsuse linux enterprise desktopcanonical ubuntu linuxlibexpat project libexpat