CVE-2016-9840

HIGH

View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing fur...

Affects 20 products across 10 vendors.

BCS7.16
CVSS 3.18.8
EPSS4.8%
Percentile91th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, requires user interaction, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2017. A high severity vulnerability affects Apple systems (CVE-2016-9840). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2017-GLOBAL-237712-H • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2016-9840?
This vulnerability was disclosed in 2017. A high severity vulnerability affects Apple systems (CVE-2016-9840). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2016-9840?
CVE-2016-9840 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. EPSS: 4.8%.
Is CVE-2016-9840 actively exploited?
No confirmed active exploitation of CVE-2016-9840 as of 2026-07-22.
How do I remediate CVE-2016-9840?
Priority: MEDIUM. Advisory: https://github.com/madler/zlib/commit/6a043145ca6e9c55184013841a67b2fef87e44c0
What systems are affected by CVE-2016-9840?
CVE-2016-9840 affects: Apple, Apple, Apple, Apple, Boost, Canonical, Debian, Fujitsu-Siemens.
Vulnerability Details
CVE IDCVE-2016-9840
BSIDBS-2017-GLOBAL-237712-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published2026-07-21
Last Modified2026-07-21
ICS Relevance0%
SourceNVD
Official Description

View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens CADRA are affected: CADRA vers:intdot/<2511, vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens CADRA Improper Input Validation, Incor

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Apple Tvos
Apple Watchos
Apple Mac Os X
Apple Iphone Os
Boost Boost
Canonical Ubuntu Linux
Debian Debian Linux
Fujitsu-Siemens &mdash;
Nodejs Node.Js
Opensuse Opensuse
Opensuse Leap
Oracle Mysql
Oracle Database Server
Oracle Jre
Oracle Jdk
Redhat Enterprise Linux Desktop
Redhat Enterprise Linux Eus
Redhat Satellite
Redhat Enterprise Linux Workstation
Redhat Enterprise Linux Server
Zlib Zlib
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 4 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashca291839d46e7af93ed9d5eb28521d67fe1a3fdb222dfc7d702c969da8b7151f64fe2cb6e7869ad233ab69b6c682210e84f6e221b9468e5f8839d88e0c98c5ec
Related CVEs affecting Apple
CVE-2007-0749 10.0 Multiple stack-based buffer overflows in the is_command function in proxy.c i... CVE-2003-0426 10.0 The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f s... CVE-2003-0502 10.0 Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attacke... CVE-2003-0694 10.0 The prescan function in Sendmail 8.12.9 allows remote attackers to execute ar... CVE-2003-1009 10.0 Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple...
View all Apple CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →