CVE Tools

CVE-2016-1839

No known exploitation. EPSS puts it in the 94th percentile. A vendor fix is available.

Published Updated Sources: CVE.org, NVD, BDU

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check whether your business systems process XML from untrusted sources (web forms, customer uploads, APIs, emails, partner feeds), and identify which devices/services use the vulnerable libxml2 versions.
  2. If you run Apple devices/OS versions listed in the fix availability, upgrade to at least: iOS 9.3.2, OS X 10.11.5, tvOS 9.2.1, or watchOS 2.2.1.
  3. If you run Linux (including Ubuntu/Debian/Red Hat Enterprise Linux) or a “web gateway” that uses libxml2, upgrade libxml2 to 2.9.4 or newer.
  4. If you can’t upgrade immediately, reduce exposure by blocking untrusted XML sources at the entry point (only accept XML from trusted systems, and reject malformed/unexpected XML content).

What it is

From the CVE record

The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

In plain language

Written by AI from the record

This is a libxml2 XML-handling bug in older iPhones, Macs, Apple TVs, and Watches that can crash apps when they process a specially crafted XML document; most small businesses only need to worry if you handle XML from untrusted sources (like customer uploads, web gateways, or partner integrations).

CVE-2016-1839 is a libxml2 heap-based buffer over-read bug in xmlDictAddString (CWE-125) that can be triggered by remote attackers via a crafted XML document, leading to a denial of service; Apple fixed this in iOS 9.3.2, OS X 10.11.5, tvOS 9.2.1, and watchOS 2.2.1, and libxml2 was fixed in 2.9.4.

If you're affected

  • App/service crashes from XML input
  • Interruption to customer-facing workflows
  • Potential denial of service on gateways
  • Time lost restoring availability

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS94th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

7.3% chance of exploitation activity in the next 30 days, which ranks it in the 94th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Attention now

Rising.

Lifecycle

24 events over 3778 days, from the signal feeds we watch.

  1. EPSS band changemoderate → lowepss band change
  2. EPSS band changelow → moderateepss band change
  3. EPSS band changemoderate → 0epss band change
  4. EPSS band change0 → moderateepss band change
  5. EPSS band changemoderate → 0epss band change
  6. EPSS band changelow → moderate

Affected products

And 12 more affected products. See all after sign-in

Technical detail

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Scored 5.5 by NVD.

How it is reached

  • Attack Vector LocalRequires local access to the vulnerable system (e.g. local login, malicious file)
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction RequiredA user must click a link, open a file, or perform some action

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality NoneNo confidentiality impact
  • Integrity NoneNo integrity impact
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for IOS, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store