2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-7547A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in ...
CVE-2016-2553Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2016-5322The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service...
CVE-2016-4989setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by...
CVE-2016-4446The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstac...
CVE-2016-4445The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands a...
CVE-2016-4444The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering...
CVE-2016-1908CRITICAL9.8The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the loca...
CVE-2016-4483HIGH7.5The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial ...
CVE-2016-0779The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute a...
CVE-2016-5011MEDIUM4.6The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate at...
CVE-2016-4468SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3...
CVE-2016-7467The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML...
CVE-2016-6811In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user...
CVE-2016-10259Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-o...
CVE-2016-8237Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitra...
CVE-2016-8235Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows loca...
CVE-2016-10323Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synoph...
CVE-2016-10322Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell m...
CVE-2016-5041HIGH7.5dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereferenc...
CVE-2016-6879The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified im...
CVE-2016-6878The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to ...
CVE-2016-10311Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by ...
CVE-2016-10310Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remo...
CVE-2016-6605Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now