2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9122 | — | — | 2.0% | Mar 28, 2017 | go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple ... |
| CVE-2016-9121 | — | — | 1.4% | Mar 28, 2017 | go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using EC... |
| CVE-2016-9737 | — | — | 0.5% | Mar 27, 2017 | IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2016-8960 | — | — | 1.5% | Mar 27, 2017 | IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of ... |
| CVE-2016-6102 | — | — | 1.1% | Mar 27, 2017 | IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to informatio... |
| CVE-2016-6056 | — | — | 0.5% | Mar 27, 2017 | IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2016-9252 | — | — | 1.8% | Mar 27, 2017 | The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 and 12.x before 12.1.2... |
| CVE-2016-9243 | HIGH | 7.5 | 3.4% | Mar 27, 2017 | HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size. |
| CVE-2016-4912 | — | — | 5.3% | Mar 27, 2017 | The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL poi... |
| CVE-2016-10225 | HIGH | 7.8 | 4.0% | Mar 27, 2017 | The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privil... |
| CVE-2016-9922 | MEDIUM | 5.5 | 0.4% | Mar 27, 2017 | The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, a... |
| CVE-2016-7474 | — | — | 0.4% | Mar 27, 2017 | In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to g... |
| CVE-2016-10273 | HIGH | 8.8 | 2.9% | Mar 26, 2017 | Multiple stack buffer overflow vulnerabilities in Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Ai... |
| CVE-2016-10272 | — | — | 1.8% | Mar 24, 2017 | LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspeci... |
| CVE-2016-10271 | — | — | 2.2% | Mar 24, 2017 | tools/tiffcrop.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read and ... |
| CVE-2016-10270 | — | — | 2.4% | Mar 24, 2017 | LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspec... |
| CVE-2016-10269 | — | — | 2.4% | Mar 24, 2017 | LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6 an... |
| CVE-2016-10268 | — | — | 1.7% | Mar 24, 2017 | tools/tiffcp.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (integer underflow and heap-based b... |
| CVE-2016-10267 | — | — | 1.7% | Mar 24, 2017 | LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a cr... |
| CVE-2016-10266 | — | — | 1.7% | Mar 24, 2017 | LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a cr... |
| CVE-2016-7797 | — | — | 3.3% | Mar 24, 2017 | Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node di... |
| CVE-2016-6206 | — | — | 3.8% | Mar 24, 2017 | Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or exec... |
| CVE-2016-3179 | MEDIUM | 5.5 | 0.3% | Mar 24, 2017 | The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (... |
| CVE-2016-3178 | MEDIUM | 5.5 | 0.3% | Mar 24, 2017 | The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (... |
| CVE-2016-2225 | — | — | 2.5% | Mar 24, 2017 | The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a de... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now