CVE-2016-9842High· 8.8▾ TwilightThe inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.2%
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
zlib >= 1.2.3.4, < 1.2.9leap = 42.1leap = 42.2opensuse = 13.2debian_linux = 8.0ubuntu_linux = 16.04ubuntu_linux = 18.04database_server = 18cjdk = 1.6.0jdk = 1.7.0jdk = 1.8.0jre = 1.6.0jre = 1.7.0jre = 1.8.0mysql >= 5.5.0, <= 5.5.61mysql >= 5.6.0, <= 5.6.41mysql >= 5.7.0, <= 5.7.23mysql >= 8.0.0, <= 8.0.12satellite = 5.8enterprise_linux_desktop = 6.0enterprise_linux_desktop = 7.0enterprise_linux_eus = 7.4enterprise_linux_eus = 7.5enterprise_linux_server = 6.0enterprise_linux_server = 7.0enterprise_linux_workstation = 6.0enterprise_linux_workstation = 7.0iphone_os < 11mac_os_x >= 10.0.0, < 10.13.0tvos < 11.0watchos < 4node.js >= 4.0.0, <= 4.1.2node.js >= 4.2.0, < 4.8.2node.js >= 6.0.0, <= 6.8.1node.js >= 6.9.0, < 6.10.2node.js >= 7.0.0, < 7.6.0Upgrade past the affected range:
zlib 1.2.9iphone_os 11mac_os_x 10.13.0tvos 11.0watchos 4node.js 7.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2016-9841Critical· 9.8inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVE-2023-45853Critical· 9.8MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field
CVE-2022-37434Critical· 9.8zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field
CVE-2026-22184High· 7.8zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz
CVE-2026-89568Medium· 5.5kernel: kho: fix size calculation in kho_preserved_memory_reserve() (CVE-2026-89568)
CVE-2026-4426Medium· 6.5A flaw was found in libarchive