CVE-2016-9841Critical· 9.8▾ Midnightinffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.5%
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
zlib >= 1.2.0, < 1.2.9leap = 42.1leap = 42.2opensuse = 13.2debian_linux = 8.0ubuntu_linux = 16.04ubuntu_linux = 18.04database_server = 18cjdk = 1.6.0jdk = 1.7.0jdk = 1.8.0jre = 1.6.0jre = 1.7.0jre = 1.8.0mysql >= 5.5.0, <= 5.5.61mysql >= 5.6.0, <= 5.6.41mysql >= 5.7.0, <= 5.7.23mysql >= 8.0.0, <= 8.0.12satellite = 5.8enterprise_linux_desktop = 6.0enterprise_linux_desktop = 7.0enterprise_linux_eus = 7.4enterprise_linux_eus = 7.5enterprise_linux_server = 6.0enterprise_linux_server = 7.0enterprise_linux_workstation = 6.0enterprise_linux_workstation = 7.0iphone_os < 11mac_os_x >= 10.0.0, < 10.13.0tvos < 11.0watchos < 4active_iq_unified_manager >= 7.3active_iq_unified_manager >= 9.5cloud_backupe-series_santricity_managemente-series_santricity_os_controller >= 11.0.0, <= 11.70.1e-series_santricity_storage_managere-series_santricity_web_servicesoncommand_balanceoncommand_insightoncommand_performance_manageroncommand_shiftoncommand_unified_manager <= 7.1oncommand_unified_manageroncommand_workflow_automationsnapmanagersolidfiresteelstore_cloud_integrated_storagestorage_replication_adapter_for_clustered_data_ontapsymantec_netbackupvasa_provider_for_clustered_data_ontap >= 7.2virtual_storage_consolehci_storage_nodenode.js >= 4.0.0, <= 4.1.2node.js >= 4.2.0, < 4.8.2node.js >= 6.0.0, <= 6.8.1node.js >= 6.9.0, < 6.10.2node.js >= 7.0.0, < 7.6.0Upgrade past the affected range:
zlib 1.2.9iphone_os 11mac_os_x 10.13.0tvos 11.0watchos 4node.js 7.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2016-9842High· 8.8The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
CVE-2023-45853Critical· 9.8MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field
CVE-2022-37434Critical· 9.8zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field
CVE-2026-22184High· 7.8zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz