2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6233 | — | — | 2.0% | Feb 17, 2017 | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers ... |
| CVE-2016-5417 | — | — | 3.4% | Feb 17, 2017 | Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc... |
| CVE-2016-4861 | — | — | 4.1% | Feb 17, 2017 | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers ... |
| CVE-2016-4327 | — | — | 1.8% | Feb 17, 2017 | Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earl... |
| CVE-2016-4316 | — | — | 4.0% | Feb 17, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web ... |
| CVE-2016-4315 | — | — | 2.8% | Feb 17, 2017 | Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio... |
| CVE-2016-4314 | — | — | 12.4% | Feb 17, 2017 | Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini... |
| CVE-2016-4312 | — | — | 6.0% | Feb 17, 2017 | XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH... |
| CVE-2016-4311 | — | — | 3.4% | Feb 17, 2017 | Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote at... |
| CVE-2016-1249 | — | — | 2.4% | Feb 17, 2017 | The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to caus... |
| CVE-2016-10134 | — | — | 83.3% | Feb 17, 2017 | SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQ... |
| CVE-2016-6062 | — | — | 0.7% | Feb 16, 2017 | IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar... |
| CVE-2016-5919 | — | — | 0.7% | Feb 16, 2017 | IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that coul... |
| CVE-2016-7293 | — | — | — | Feb 16, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-8678 | — | — | 1.6% | Feb 15, 2017 | The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.0 allows remote attackers to cause a ... |
| CVE-2016-8676 | — | — | 1.7% | Feb 15, 2017 | The get_vlc2 function in get_bits.h in Libav 11.9 allows remote attackers to cause a denial of service (NULL pointer der... |
| CVE-2016-8675 | — | — | 1.7% | Feb 15, 2017 | The get_vlc2 function in get_bits.h in Libav before 11.9 allows remote attackers to cause a denial of service (NULL poin... |
| CVE-2016-8674 | — | — | 1.4% | Feb 15, 2017 | The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-a... |
| CVE-2016-7499 | — | — | 1.4% | Feb 15, 2017 | The sbr_make_f_master function in aacsbr.c in Libav 11.7 allows remote attackers to cause a denial of service (divide-by... |
| CVE-2016-7477 | — | — | 1.7% | Feb 15, 2017 | The ff_put_pixels8_xy2_mmx function in rnd_template.c in Libav 11.7 allows remote attackers to cause a denial of service... |
| CVE-2016-7393 | — | — | 1.6% | Feb 15, 2017 | Stack-based buffer overflow in the aac_sync function in aac_parser.c in Libav before 11.5 allows remote attackers to cau... |
| CVE-2016-7392 | — | — | 1.9% | Feb 15, 2017 | Heap-based buffer overflow in the pstoedit_suffix_table_init function in output-pstoedit.c in AutoTrace 0.31.1 allows re... |
| CVE-2016-9706 | — | — | 1.8% | Feb 15, 2017 | IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by... |
| CVE-2016-9010 | — | — | 0.8% | Feb 15, 2017 | IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By ... |
| CVE-2016-8972 | — | — | 1.4% | Feb 15, 2017 | IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now