CVE detail
CVE-2016-9841
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
35 source links · newest first
- Siemens CADRACISA Alerts
cations, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2005-2096 zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow,
governmentwww.cisa.govJul 21, 2026, 12:00 PM - https://cert-portal.siemens.com/productcert/html/ssa-470355.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMay 23, 2017, 4:29 AM - https://www.oracle.com/security-alerts/cpujul2020.htmlwww.oracle.com
No excerpt available.
Vendor Advisorywww.oracle.comMay 23, 2017, 4:29 AM - https://wiki.mozilla.org/images/0/09/Zlib-report.pdfwiki.mozilla.org
No excerpt available.
Third Party Advisorywiki.mozilla.orgMay 23, 2017, 4:29 AM - https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlibwiki.mozilla.org
No excerpt available.
Third Party Advisorywiki.mozilla.orgMay 23, 2017, 4:29 AM - https://usn.ubuntu.com/4292-1/usn.ubuntu.com
No excerpt available.
Third Party Advisoryusn.ubuntu.comMay 23, 2017, 4:29 AM - https://usn.ubuntu.com/4246-1/usn.ubuntu.com
No excerpt available.
Third Party Advisoryusn.ubuntu.comMay 23, 2017, 4:29 AM - https://support.apple.com/HT208144support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comMay 23, 2017, 4:29 AM - https://support.apple.com/HT208115support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comMay 23, 2017, 4:29 AM - https://support.apple.com/HT208113support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comMay 23, 2017, 4:29 AM - https://support.apple.com/HT208112support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comMay 23, 2017, 4:29 AM - https://security.netapp.com/advisory/ntap-20171019-0001/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comMay 23, 2017, 4:29 AM - https://security.gentoo.org/glsa/202007-54security.gentoo.org
No excerpt available.
Vendor Advisorysecurity.gentoo.orgMay 23, 2017, 4:29 AM - https://security.gentoo.org/glsa/201701-56security.gentoo.org
No excerpt available.
Vendor Advisorysecurity.gentoo.orgMay 23, 2017, 4:29 AM No excerpt available.
Vendor Advisorylists.debian.orgMay 23, 2017, 4:29 AMNo excerpt available.
Vendor Advisorylists.debian.orgMay 23, 2017, 4:29 AMNo excerpt available.
Exploitgithub.comMay 23, 2017, 4:29 AM- https://bugzilla.redhat.com/show_bug.cgi?id=1402346bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 23, 2017, 4:29 AM - https://access.redhat.com/errata/RHSA-2017:3453access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2017, 4:29 AM - https://access.redhat.com/errata/RHSA-2017:3047access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2017, 4:29 AM - https://access.redhat.com/errata/RHSA-2017:3046access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2017, 4:29 AM - https://access.redhat.com/errata/RHSA-2017:2999access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2017, 4:29 AM - https://access.redhat.com/errata/RHSA-2017:1222access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2017, 4:29 AM - https://access.redhat.com/errata/RHSA-2017:1221access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2017, 4:29 AM - https://access.redhat.com/errata/RHSA-2017:1220access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2017, 4:29 AM - http://www.securitytracker.com/id/1039596www.securitytracker.com
No excerpt available.
Third Party Advisorywww.securitytracker.comMay 23, 2017, 4:29 AM - http://www.securitytracker.com/id/1039427www.securitytracker.com
No excerpt available.
Third Party Advisorywww.securitytracker.comMay 23, 2017, 4:29 AM - http://www.securityfocus.com/bid/95131www.securityfocus.com
No excerpt available.
Exploitwww.securityfocus.comMay 23, 2017, 4:29 AM No excerpt available.
Vendor Advisorywww.oracle.comMay 23, 2017, 4:29 AMNo excerpt available.
Vendor Advisorywww.oracle.comMay 23, 2017, 4:29 AMNo excerpt available.
Vendor Advisorywww.oracle.comMay 23, 2017, 4:29 AM- http://www.openwall.com/lists/oss-security/2016/12/05/21www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 23, 2017, 4:29 AM - http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.htmllists.opensuse.org
No excerpt available.
Third Party Advisorylists.opensuse.orgMay 23, 2017, 4:29 AM - http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.htmllists.opensuse.org
No excerpt available.
Third Party Advisorylists.opensuse.orgMay 23, 2017, 4:29 AM - http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.htmllists.opensuse.org
No excerpt available.
Third Party Advisorylists.opensuse.orgMay 23, 2017, 4:29 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2016-9843CVSS 9.8 · Critical
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
- CVE-2016-9842CVSS 8.8 · High
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
- CVE-2016-9840CVSS 8.8 · High
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
32 mentions - CVE-2020-2601CVSS 6.8 · Medium
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1;…
- CVE-2020-2593CVSS 4.8 · Medium
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1…
- CVE-2020-2590CVSS 3.7 · Low
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1;…