CVE-2016-9063: Debian Linux

Critical severity, CVSS 9.8. EPSS: 5.5% chance of exploitation in the next 30 days.

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Mozilla Firefox: before 50 (fixed in 50)
  • Python Python: from 2.7.0, before 2.7.15 (fixed in 2.7.15); from 3.3.0, before 3.3.7 (fixed in 3.3.7); from 3.4.0, before 3.4.7 (fixed in 3.4.7); from 3.5.0, before 3.5.4 (fixed in 3.5.4); from 3.6.0, before 3.6.2 (fixed in 3.6.2)

Published 2018-06-11. Last modified 2026-10-08.