← Vulnerability feed

Vulnerability record · CVE-2016-4493 · published 24 February 2017

CVE-2016-4493: Gnu libiberty out-of-bounds read vulnerability

Gnu · Libiberty

The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted binary.

5.5 CVSS 3.0 Medium EPSS 1.6% · top 25.0% CWE-125 · Out-of-bounds read
5.5CVSS 3.0 base score, v2 4.3
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted binary.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-4493 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2016-2226Gnu libiberty memory buffer overflow vulnerabilityInteger overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executabl…EPSS 7.3%7.5CVE-2016-6131Gnu libiberty improper input validation vulnerabilityThe demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the ref…EPSS 4.6%5.5CVE-2016-4487Gnu libiberty use after free vulnerabilityUse-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…EPSS 1.7%5.5CVE-2016-4488Gnu libiberty use after free vulnerabilityUse-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…EPSS 1.7%5.5CVE-2016-4489Gnu libiberty integer overflow vulnerabilityInteger overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a c…EPSS 1.7%5.5CVE-2016-4490Gnu libiberty integer overflow vulnerabilityInteger overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted bina…EPSS 1.8%5.5CVE-2016-4491Gnu libiberty memory buffer overflow vulnerabilityThe d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a cra…EPSS 1.8%5.0CVE-2012-3509Gnu binutils vulnerabilityMultiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as …EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2016-4493), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.