2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4030Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUB...
CVE-2016-2567secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (G...
CVE-2016-2566Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.
CVE-2016-2565Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages, ...
CVE-2016-2036The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9...
CVE-2016-10326In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() func...
CVE-2016-10325In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() ...
CVE-2016-10324In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function...
CVE-2016-6143SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, ak...
CVE-2016-4970HIGH7.5handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers t...
CVE-2016-4800The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote atta...
CVE-2016-4068Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attacker...
CVE-2016-3106Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.
CVE-2016-2555SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi...
CVE-2016-2104Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary we...
CVE-2016-1915Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 ...
CVE-2016-1914Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server...
CVE-2016-1132Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.
CVE-2016-10123Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.
CVE-2016-10122Firejail does not properly clean environment variables, which allows local users to gain privileges.
CVE-2016-10121Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileg...
CVE-2016-10120Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local ...
CVE-2016-10119Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.
CVE-2016-10118Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /.
CVE-2016-10117Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting o...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now