Disclosure summary
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Source-reported weakness categories
NVD-CWE-noinfo
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2016-9840
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| boost | boost | * {"versionEndExcluding":"1.78.0"} |
| zlib | zlib | * {"versionStartIncluding":"1.2.0.6","versionEndExcluding":"1.2.9"} |
| opensuse | leap | 42.1 |
| opensuse | leap | 42.2 |
| opensuse | opensuse | 13.2 |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| oracle | database_server | 18c |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jre | 1.6.0 |
| oracle | jre | 1.7.0 |
| oracle | jre | 1.8.0 |
| oracle | mysql | * {"versionStartIncluding":"8.0.0","versionEndIncluding":"8.0.12"} |
| redhat | satellite | 5.8 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_eus | 7.4 |
| redhat | enterprise_linux_eus | 7.5 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| apple | iphone_os | * {"versionEndExcluding":"11"} |
| apple | mac_os_x | * {"versionStartIncluding":"10.0.0","versionEndExcluding":"10.13.0"} |
| apple | tvos | * {"versionEndExcluding":"11.0"} |
| apple | watchos | * {"versionEndExcluding":"4"} |
| nodejs | node.js | * {"versionStartIncluding":"7.0.0","versionEndExcluding":"7.6.0"} |
| nodejs | node.js | * {"versionStartIncluding":"6.9.0","versionEndExcluding":"6.10.2"} |
Original records & references
- NIST NVD record
- CVE Program record
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- bugzilla.redhat.com — Issue Tracking, Third Party Advisory
- github.com — Patch, Third Party Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- security.gentoo.org — Third Party Advisory
- security.gentoo.org — Third Party Advisory
- support.apple.com — Third Party Advisory
- support.apple.com — Third Party Advisory
- support.apple.com — Third Party Advisory
- support.apple.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- wiki.mozilla.org — Third Party Advisory
- wiki.mozilla.org — Broken Link
- www.oracle.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- bugzilla.redhat.com — Issue Tracking, Third Party Advisory
- github.com — Patch, Third Party Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- security.gentoo.org — Third Party Advisory
- security.gentoo.org — Third Party Advisory
- support.apple.com — Third Party Advisory
- support.apple.com — Third Party Advisory
- support.apple.com — Third Party Advisory
- support.apple.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- wiki.mozilla.org — Third Party Advisory
- wiki.mozilla.org — Broken Link
- www.oracle.com — Third Party Advisory
- cert-portal.siemens.com
PUBLISHED 2017-05-23T00:29:01-04:00
MODIFIED 2026-10-08T18:16:39-04:00
INGESTED 2026-10-10T20:50:18-04:00