CVE-2016-9063

Description

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.423

Associated Vulnerability

VulnerabilityOS Platform
Update for Mozilla Firefox (50.0)Windows
Update for Mozilla Firefox x64 (50.0)Windows
Update for Mozilla Firefox (50.0.1)Windows
Update for Mozilla Firefox x64 (50.0.1)Windows
Update for Mozilla Firefox (50.0.2)Windows
Update for Mozilla Firefox x64 (50.0.2)Windows
Update for Mozilla Firefox (50.1.0)Windows
Update for Mozilla Firefox x64 (50.1.0)Windows
Vulnerabilities CVE-2016-9063 are affected in Python 2.7.14Windows
Multiple Vulnerabilities are affected in Python 3.3.6Windows
Vulnerabilities CVE-2014-4616,CVE-2016-9063 are affected in Python 3.4.6Windows
Vulnerabilities CVE-2016-9063 are affected in Python 3.5.3Windows
Vulnerabilities CVE-2016-9063 are affected in Python 3.6.1Windows
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (50.1.0)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (50.0)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (50.0.2)Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.6 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.6 Combo Update - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.5 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.4 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.4 Combo Update - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.3Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.3 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.1Mac
Multiple vulnerabilities are fixed in Security Update 2017-001 macOS High Sierra v10.13.1Mac
Multiple vulnerabilities are fixed in Security Update 2017-001 macOS High Sierra v10.13Mac
Vulnerabilities CVE-2016-9063,CVE-2016-9070 are affected in Mozilla Firefox for Mac 49.0.2Mac
expat security update(DSA-3898-1) expat_2.1.0-6+deb8u4_kfreebsd-i386.debLinux
SUSE-SU-2017:2299-1(SUSE Linux Enterprise Desktop 12-SP2 ) expat-2.1.0-21.3.1.x86_64.rpmLinux
SUSE-SU-2017:2299-1(SUSE Linux Enterprise Desktop 12-SP2 ) expat-debuginfo-2.1.0-21.3.1.x86_64.rpmLinux
SUSE-SU-2017:2299-1(SUSE Linux Enterprise Desktop 12-SP2 ) expat-debuginfo-32bit-2.1.0-21.3.1.x86_64.rpmLinux
SUSE-SU-2017:2299-1(SUSE Linux Enterprise Desktop 12-SP2 ) expat-debugsource-2.1.0-21.3.1.x86_64.rpmLinux
SUSE-SU-2017:2299-1(SUSE Linux Enterprise Desktop 12-SP2 ) libexpat1-2.1.0-21.3.1.x86_64.rpmLinux
SUSE-SU-2017:2299-1(SUSE Linux Enterprise Desktop 12-SP2 ) libexpat1-32bit-2.1.0-21.3.1.x86_64.rpmLinux
SUSE-SU-2017:2299-1(SUSE Linux Enterprise Desktop 12-SP2 ) libexpat1-debuginfo-2.1.0-21.3.1.x86_64.rpmLinux
SUSE-SU-2017:2299-1(SUSE Linux Enterprise Desktop 12-SP2 ) libexpat1-debuginfo-32bit-2.1.0-21.3.1.x86_64.rpmLinux
SUSE-SU-2017:2375-1(SUSE Linux Enterprise Server 11-SP4 ) expat-2.0.1-88.42.3.2.x86_64.rpmLinux
SUSE-SU-2017:2375-1(SUSE Linux Enterprise Server 11-SP4 ) libexpat1-2.0.1-88.42.3.2.x86_64.rpmLinux
SUSE-SU-2017:2375-1(SUSE Linux Enterprise Server 11-SP4 ) libexpat1-32bit-2.0.1-88.42.3.2.x86_64.rpmLinux
SUSE-SU-2019:2872-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-68.2.0-109.95.2.x86_64.rpmLinux
SUSE-SU-2019:2872-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-debuginfo-68.2.0-109.95.2.x86_64.rpmLinux
SUSE-SU-2019:2872-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-debugsource-68.2.0-109.95.2.x86_64.rpmLinux
SUSE-SU-2019:2872-1(SUSE Linux Enterprise Desktop 12-SP4 ) MozillaFirefox-translations-common-68.2.0-109.95.2.x86_64.rpmLinux
SUSE-SU-2020:0497-1(SUSE Linux Enterprise Desktop 12-SP4 ) libpython3_4m1_0-3.4.10-25.39.2.x86_64.rpmLinux
SUSE-SU-2020:0497-1(SUSE Linux Enterprise Desktop 12-SP4 ) libpython3_4m1_0-debuginfo-3.4.10-25.39.2.x86_64.rpmLinux
SUSE-SU-2020:0497-1(SUSE Linux Enterprise Desktop 12-SP4 ) python3-3.4.10-25.39.3.x86_64.rpmLinux
SUSE-SU-2020:0497-1(SUSE Linux Enterprise Desktop 12-SP4 ) python3-base-3.4.10-25.39.2.x86_64.rpmLinux
SUSE-SU-2020:0497-1(SUSE Linux Enterprise Desktop 12-SP4 ) python3-base-debuginfo-3.4.10-25.39.2.x86_64.rpmLinux
SUSE-SU-2020:0497-1(SUSE Linux Enterprise Desktop 12-SP4 ) python3-base-debugsource-3.4.10-25.39.2.x86_64.rpmLinux
SUSE-SU-2020:0497-1(SUSE Linux Enterprise Desktop 12-SP4 ) python3-curses-3.4.10-25.39.3.x86_64.rpmLinux
SUSE-SU-2020:0497-1(SUSE Linux Enterprise Desktop 12-SP4 ) python3-curses-debuginfo-3.4.10-25.39.3.x86_64.rpmLinux
SUSE-SU-2020:0497-1(SUSE Linux Enterprise Desktop 12-SP4 ) python3-debuginfo-3.4.10-25.39.3.x86_64.rpmLinux
SUSE-SU-2020:0497-1(SUSE Linux Enterprise Desktop 12-SP4 ) python3-debugsource-3.4.10-25.39.3.x86_64.rpmLinux
Integer Overflow or Wraparound Vulnerability (CVE-2016-9063)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304314Update for Mozilla Firefox x64 (50.0)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304365Update for Mozilla Firefox x64 (50.0.1)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304376Update for Mozilla Firefox x64 (50.0.2)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304411Update for Mozilla Firefox x64 (50.1.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601312Security Update 2017-001 macOS High Sierra v10.13.1
PATCH-601345Security Update 2017-001 macOS High Sierra v10.13
PATCH-611870Mozilla Firefox For Mac (142.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234