CVE-2016-0718: Apple Mac OS X

Critical severity, CVSS 9.8. EPSS: 13.3% chance of exploitation in the next 30 days.

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

Affected products

  • Apple Mac OS X: from 10.11.0, up to and including 10.11.5
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Libexpat Project Libexpat: before 2.2.0 (fixed in 2.2.0)
  • McAfee Policy Auditor: before 6.5.1 (fixed in 6.5.1)
  • Mozilla Firefox: before 48.0 (fixed in 48.0)
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Python Python: from 2.7.0, before 2.7.15 (fixed in 2.7.15); from 3.3.0, before 3.3.7 (fixed in 3.3.7); from 3.4.0, before 3.4.7 (fixed in 3.4.7); from 3.5.0, before 3.5.4 (fixed in 3.5.4); from 3.6.0, before 3.6.2 (fixed in 3.6.2)
  • Suse Linux Enterprise Debuginfo: version 11 only
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Server: version 11 only; version 12 only
  • Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only
  • Suse Studio Onsite: version 1.3 only

Published 2016-05-26. Last modified 2026-10-08.