CVE-2016-9063 is a critical integer overflow vulnerability in the Expat XML parsing library, affecting Firefox versions prior to 50, as well as various Debian and Python products utilizing this library. With a CVSS score of 9.8, it allows for unauthenticated, low-complexity remote attacks that can lead to complete compromise of confidentiality, integrity, and availability. While the EPSS score is low and it's not on the KEV catalog, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and community discussion and media coverage are minimal, suggesting limited active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 50CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
>= 2.7.0, < 2.7.15CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.