2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10117——Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting o...
CVE-2016-6348——JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
CVE-2016-5856——Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privil...
CVE-2016-5313——Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.
CVE-2016-4897——Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search...
CVE-2016-4896——SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthoriz...
CVE-2016-4895——SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.
CVE-2016-4894——SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors.
CVE-2016-4893——SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQ...
CVE-2016-4892——Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or ...
CVE-2016-4891——Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authent...
CVE-2016-4337——SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e...
CVE-2016-2803——Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through ...
CVE-2016-1179——Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2....
CVE-2016-1178——The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers t...
CVE-2016-9959——game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
CVE-2016-9958——game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
CVE-2016-9957——Stack-based buffer overflow in game-music-emu before 0.6.1.
CVE-2016-6808——Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
CVE-2016-4459——Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
CVE-2016-8719MEDIUM6.1An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131...
CVE-2016-8718HIGH8.8An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wi...
CVE-2016-8716HIGH7.5An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-...
CVE-2016-7958——In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was a...
CVE-2016-7957——In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now