2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-4894SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors.
CVE-2016-4893SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQ...
CVE-2016-4892Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or ...
CVE-2016-4891Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authent...
CVE-2016-4337SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e...
CVE-2016-2803Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through ...
CVE-2016-1179Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2....
CVE-2016-1178The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers t...
CVE-2016-9959game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
CVE-2016-9958game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
CVE-2016-9957Stack-based buffer overflow in game-music-emu before 0.6.1.
CVE-2016-6808Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
CVE-2016-4459Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
CVE-2016-7958In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was a...
CVE-2016-7957In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file...
CVE-2016-7552On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows...
CVE-2016-7547A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in ...
CVE-2016-2553Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2016-5322The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service...
CVE-2016-4989setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by...
CVE-2016-4446The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstac...
CVE-2016-4445The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands a...
CVE-2016-4444The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering...
CVE-2016-0779The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute a...
CVE-2016-4468SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now