← Vulnerability feed

Vulnerability record · CVE-2016-2226 · published 24 February 2017

CVE-2016-2226: Gnu libiberty memory buffer overflow vulnerability

Gnu · Libiberty

Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.

7.8 CVSS 3.0 High EPSS 7.3% · top 5.9% CWE-119 · Memory buffer overflowCWE-190 · Integer overflow
7.8CVSS 3.0 base score, v2 6.8
7.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-2226 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2016-6131Gnu libiberty improper input validation vulnerabilityThe demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the ref…EPSS 4.6%5.5CVE-2016-4487Gnu libiberty use after free vulnerabilityUse-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…EPSS 1.7%5.5CVE-2016-4488Gnu libiberty use after free vulnerabilityUse-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…EPSS 1.7%5.5CVE-2016-4489Gnu libiberty integer overflow vulnerabilityInteger overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a c…EPSS 1.7%5.5CVE-2016-4490Gnu libiberty integer overflow vulnerabilityInteger overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted bina…EPSS 1.8%5.5CVE-2016-4491Gnu libiberty memory buffer overflow vulnerabilityThe d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a cra…EPSS 1.8%5.5CVE-2016-4493Gnu libiberty out-of-bounds read vulnerabilityThe demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of serv…EPSS 1.6%5.0CVE-2012-3509Gnu binutils vulnerabilityMultiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as …EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2016-2226), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.