CVE-2016-6855 describes an out-of-bounds write vulnerability in Eye of GNOME (eog) versions 3.16.5 through 3.20.4, when used with glib before 2.44.1. This flaw, affecting Canonical, Fedora, GNOME, and OpenSUSE, allows remote attackers to cause a denial of service by providing invalid UTF-8 to GMarkup. Rated 7.5 HIGH on CVSSv3, it has a low attack complexity and no user interaction required, leading to a high impact on availability. While there is an ExploitDB entry (EDB-40291), there are no known active exploits, Metasploit modules, or Nuclei templates, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
23CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:* | ||
24CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.