2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4660 | — | — | 1.7% | Feb 20, 2017 | An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b... |
| CVE-2016-4617 | — | — | 0.3% | Feb 20, 2017 | An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves a sandbox escape r... |
| CVE-2016-4613 | — | — | 1.1% | Feb 20, 2017 | An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iT... |
| CVE-2016-7511 | — | — | 1.5% | Feb 17, 2017 | Integer overflow in the dwarf_die_deliv.c in libdwarf 20160613 allows remote attackers to cause a denial of service (cra... |
| CVE-2016-7111 | — | — | 1.0% | Feb 17, 2017 | MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, wh... |
| CVE-2016-6875 | — | — | 2.2% | Feb 17, 2017 | Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vector... |
| CVE-2016-6874 | — | — | 2.0% | Feb 17, 2017 | The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown v... |
| CVE-2016-6873 | — | — | 2.2% | Feb 17, 2017 | Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors... |
| CVE-2016-6872 | — | — | 2.2% | Feb 17, 2017 | Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via u... |
| CVE-2016-6871 | — | — | 2.3% | Feb 17, 2017 | Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vector... |
| CVE-2016-6870 | — | — | 2.2% | Feb 17, 2017 | Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM ... |
| CVE-2016-6252 | — | — | 0.4% | Feb 17, 2017 | Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap. |
| CVE-2016-6190 | — | — | 1.2% | Feb 17, 2017 | SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote ... |
| CVE-2016-5364 | — | — | 1.9% | Feb 17, 2017 | Cross-site scripting (XSS) vulnerability in manage_custom_field_edit_page.php in MantisBT 1.2.19 and earlier allows remo... |
| CVE-2016-6251 | — | — | — | Feb 17, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-9955 | — | — | 1.2% | Feb 17, 2017 | The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof sig... |
| CVE-2016-9831 | — | — | 2.1% | Feb 17, 2017 | Heap-based buffer overflow in the parseSWF_RGBA function in parser.c in the listswf tool in libming 0.4.7 allows remote ... |
| CVE-2016-9829 | — | — | 2.1% | Feb 17, 2017 | Heap-based buffer overflow in the parseSWF_DEFINEFONT function in parser.c in the listswf tool in libming 0.4.7 allows r... |
| CVE-2016-9828 | — | — | 1.9% | Feb 17, 2017 | The dumpBuffer function in read.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of serv... |
| CVE-2016-9827 | — | — | 1.8% | Feb 17, 2017 | The _iprintf function in outputtxt.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of s... |
| CVE-2016-9814 | — | — | 2.4% | Feb 17, 2017 | The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library be... |
| CVE-2016-9773 | — | — | 1.8% | Feb 17, 2017 | Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remo... |
| CVE-2016-9637 | — | — | 0.4% | Feb 17, 2017 | The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow l... |
| CVE-2016-9139 | — | — | 0.8% | Feb 17, 2017 | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, ... |
| CVE-2016-8652 | — | — | 48.2% | Feb 17, 2017 | The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now