2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7547 | — | — | 92.7% | Apr 12, 2017 | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in ... |
| CVE-2016-2553 | — | — | — | Apr 11, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-5322 | — | — | 1.6% | Apr 11, 2017 | The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service... |
| CVE-2016-4989 | — | — | 0.5% | Apr 11, 2017 | setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by... |
| CVE-2016-4446 | — | — | 0.5% | Apr 11, 2017 | The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstac... |
| CVE-2016-4445 | — | — | 0.5% | Apr 11, 2017 | The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands a... |
| CVE-2016-4444 | — | — | 0.5% | Apr 11, 2017 | The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering... |
| CVE-2016-1908 | CRITICAL | 9.8 | 13.7% | Apr 11, 2017 | The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the loca... |
| CVE-2016-4483 | HIGH | 7.5 | 6.2% | Apr 11, 2017 | The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial ... |
| CVE-2016-0779 | — | — | 9.9% | Apr 11, 2017 | The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute a... |
| CVE-2016-5011 | MEDIUM | 4.6 | 0.5% | Apr 11, 2017 | The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate at... |
| CVE-2016-4468 | — | — | 2.1% | Apr 11, 2017 | SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3... |
| CVE-2016-7467 | — | — | 1.9% | Apr 11, 2017 | The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML... |
| CVE-2016-6811 | — | — | 2.6% | Apr 11, 2017 | In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user... |
| CVE-2016-10259 | — | — | 1.5% | Apr 11, 2017 | Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-o... |
| CVE-2016-8237 | — | — | 3.3% | Apr 10, 2017 | Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitra... |
| CVE-2016-8235 | — | — | 0.4% | Apr 10, 2017 | Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows loca... |
| CVE-2016-10323 | — | — | 0.6% | Apr 10, 2017 | Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synoph... |
| CVE-2016-10322 | — | — | 1.9% | Apr 10, 2017 | Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell m... |
| CVE-2016-5041 | HIGH | 7.5 | 3.4% | Apr 10, 2017 | dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereferenc... |
| CVE-2016-6879 | — | — | 0.6% | Apr 10, 2017 | The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified im... |
| CVE-2016-6878 | — | — | 1.2% | Apr 10, 2017 | The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to ... |
| CVE-2016-10311 | — | — | 2.2% | Apr 10, 2017 | Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by ... |
| CVE-2016-10310 | — | — | 2.0% | Apr 10, 2017 | Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remo... |
| CVE-2016-6605 | — | — | 1.4% | Apr 10, 2017 | Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now