EXPOSURES › CVE-2016-9841
CVE-2016-9841
CRITICAL
DETAIL
SourceNVD · cve
Published2017-05-23
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-9841 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
NetApp · vendorOracle · vendorapple · vendorcanonical · vendordebian · vendornodejs · vendoropensuse · vendorredhat · vendorzlib · vendoractive iq unified manager · productcloud backup · productdatabase server · productdebian linux · producte-series santricity management · producte-series santricity os controller · producte-series santricity storage manager · producte-series santricity web services · productenterprise linux desktop · productenterprise linux eus · productenterprise linux server · productenterprise linux workstation · producthci storage node · productiphone os · productjdk · productjre · productleap · productmac os x · productmysql · productnode.js · productoncommand balance · productoncommand insight · productoncommand performance manager · productoncommand shift · productoncommand unified manager · productoncommand workflow automation · productopensuse · productsatellite · productsnapmanager · productsolidfire · productsteelstore cloud integrated storage · productstorage replication adapter for clustered data ontap · productsymantec netbackup · producttvos · productubuntu linux · productvasa provider for clustered data ontap · productvirtual storage console · productwatchos · productzlib · product
DESCRIPTION
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
SENTIMENT · TRUSTED SOURCES
synthesis
neutral
+0.00
No coverage found for CVE-2016-9841 in the provided sources; sources discuss unrelated CVEs or generic vendor pages.
Neutral; source only restates the CVE fact without commentary on vendor handling.
"inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic."
Neutral; generic vendor database page with no specific coverage of CVE-2016-9841.
Neutral; discusses a different CVE (CVE-2008-4128) and unrelated vendor (Cisco).
"CISA Warns of Decades Old Cisco IOS Vulnerability Actively Exploited in Attacks"
Neutral; generic vendor product page with no specific coverage of CVE-2016-9841.
Neutral; generic CVE database page with no specific coverage of CVE-2016-9841.
Neutral; generic NVD page with no specific coverage of CVE-2016-9841.
AFFECTED FEDRAMP PRODUCTS · 11
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Cloud Insights NetApp |
In Process |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |