2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6348 | — | — | 1.3% | Apr 12, 2017 | JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack. |
| CVE-2016-5856 | — | — | 0.6% | Apr 12, 2017 | Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privil... |
| CVE-2016-5313 | — | — | 4.6% | Apr 12, 2017 | Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands. |
| CVE-2016-4897 | — | — | 1.1% | Apr 12, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search... |
| CVE-2016-4896 | — | — | 1.3% | Apr 12, 2017 | SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthoriz... |
| CVE-2016-4895 | — | — | 2.0% | Apr 12, 2017 | SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors. |
| CVE-2016-4894 | — | — | 2.1% | Apr 12, 2017 | SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors. |
| CVE-2016-4893 | — | — | 1.6% | Apr 12, 2017 | SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQ... |
| CVE-2016-4892 | — | — | 1.3% | Apr 12, 2017 | Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or ... |
| CVE-2016-4891 | — | — | 1.0% | Apr 12, 2017 | Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authent... |
| CVE-2016-4337 | — | — | 2.3% | Apr 12, 2017 | SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e... |
| CVE-2016-2803 | — | — | 1.5% | Apr 12, 2017 | Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through ... |
| CVE-2016-1179 | — | — | 1.2% | Apr 12, 2017 | Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.... |
| CVE-2016-1178 | — | — | 1.3% | Apr 12, 2017 | The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers t... |
| CVE-2016-9959 | — | — | 2.3% | Apr 12, 2017 | game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values. |
| CVE-2016-9958 | — | — | 2.3% | Apr 12, 2017 | game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations. |
| CVE-2016-9957 | — | — | 1.9% | Apr 12, 2017 | Stack-based buffer overflow in game-music-emu before 0.6.1. |
| CVE-2016-6808 | — | — | 19.0% | Apr 12, 2017 | Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42. |
| CVE-2016-4459 | — | — | 2.7% | Apr 12, 2017 | Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9. |
| CVE-2016-8719 | MEDIUM | 6.1 | 0.8% | Apr 12, 2017 | An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131... |
| CVE-2016-8718 | HIGH | 8.8 | 0.5% | Apr 12, 2017 | An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wi... |
| CVE-2016-8716 | HIGH | 7.5 | 0.8% | Apr 12, 2017 | An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-... |
| CVE-2016-7958 | — | — | 2.2% | Apr 12, 2017 | In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was a... |
| CVE-2016-7957 | — | — | 1.7% | Apr 12, 2017 | In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file... |
| CVE-2016-7552 | — | — | 93.2% | Apr 12, 2017 | On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now