2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-3101MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to i...
CVE-2016-2781MEDIUM4.6chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIO...
CVE-2016-6188MEDIUM6.5Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number o...
CVE-2016-4571MEDIUM5.5The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a de...
CVE-2016-4570MEDIUM5.5The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial ...
CVE-2016-8216MEDIUM6.7EMC Data Domain OS (DD OS) 5.4 all versions, EMC Data Domain OS (DD OS) 5.5 family all versions prior to 5.5.5.0, EMC Da...
CVE-2016-0919MEDIUM6.1EMC RSA Web Threat Detection version 5.0, RSA Web Threat Detection version 5.1, RSA Web Threat Detection version 5.1.2 h...
CVE-2016-0371MEDIUM5.5The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application ...
CVE-2016-3022MEDIUM6.5IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due...
CVE-2016-2050MEDIUM6.5The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers to cause a denial of service (out-of-bou...
CVE-2016-2402MEDIUM5.9OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a c...
CVE-2016-2518MEDIUM5.3The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-o...
CVE-2016-9401MEDIUM5.5popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
CVE-2016-7410MEDIUM5.5The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (...
CVE-2016-4055MEDIUM6.5The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of servi...
CVE-2016-7906MEDIUM5.5magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a cr...
CVE-2016-7799MEDIUM6.5MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds r...
CVE-2016-7101MEDIUM6.5The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) v...
CVE-2016-9811MEDIUM4.7The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc,...
CVE-2016-10027MEDIUM5.9Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allow...
CVE-2016-10011MEDIUM6.2authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which mig...
CVE-2016-9916MEDIUM6.5Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial ...
CVE-2016-9915MEDIUM6.5Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial...
CVE-2016-9914MEDIUM6.5Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of ser...
CVE-2016-9913MEDIUM6.5Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privi...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now