CVE-2016-9842

CVSS 8.8 - HIGH
Description

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

Affected Products
36
Vendor Product Version
zlib zlib All versions
opensuse leap 42.1
opensuse leap 42.2
opensuse opensuse 13.2
debian debian_linux 8.0
canonical ubuntu_linux 16.04
canonical ubuntu_linux 18.04
oracle database_server 18c
oracle jdk 1.6.0
oracle jdk 1.7.0
oracle jdk 1.8.0
oracle jre 1.6.0
oracle jre 1.7.0
oracle jre 1.8.0
oracle mysql All versions
oracle mysql All versions
oracle mysql All versions
oracle mysql All versions
redhat satellite 5.8
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_eus 7.4
redhat enterprise_linux_eus 7.5
redhat enterprise_linux_server 6.0
redhat enterprise_linux_server 7.0
redhat enterprise_linux_workstation 6.0
redhat enterprise_linux_workstation 7.0
apple iphone_os All versions
apple mac_os_x All versions
apple tvos All versions
apple watchos All versions
nodejs node.js All versions
nodejs node.js All versions
nodejs node.js All versions
nodejs node.js All versions
nodejs node.js All versions
Weakness Types
NVD-CWE-noinfo CWE-1335
CVE Information
CVE ID:
CVE-2016-9842
Published:
2017-05-23
Modified:
2026-05-13
CVSS Score:
8.8
Severity:
HIGH
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Vendors
nodejs redhat oracle zlib canonical apple debian opensuse
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL