AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-8863

CRITICAL · CVSS 9.8 EPSS 8.49%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-03-07 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-8863
Severity
CRITICAL
CVSS
9.8
EPSS
8.49%

Original NVD Description

Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.