VDB

CVE-2016-10164

CVE-2016-10164 PUBLISHED

Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.

EPSS 6.20% · 91.0th percentile

Risk Scores

EPSS Score
6.20%
91.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibxpm1:3.5.10-1, 0
Ubuntu:16.04:LTSlibxpm0, 1:3.5.11-1

Timeline

  • Dec 31, 2016 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 1, 2023 EPSS Score
  • May 24, 2023 EPSS Score
  • Sep 6, 2023 EPSS Score
  • Oct 28, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›