2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-4987MEDIUM6.5Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbi...
CVE-2016-3101MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to i...
CVE-2016-2781MEDIUM4.6chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIO...
CVE-2016-6188MEDIUM6.5Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number o...
CVE-2016-4571MEDIUM5.5The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a de...
CVE-2016-4570MEDIUM5.5The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial ...
CVE-2016-8216MEDIUM6.7EMC Data Domain OS (DD OS) 5.4 all versions, EMC Data Domain OS (DD OS) 5.5 family all versions prior to 5.5.5.0, EMC Da...
CVE-2016-6649MEDIUM6.7EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by m...
CVE-2016-6648MEDIUM4.4EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by s...
CVE-2016-0919MEDIUM6.1EMC RSA Web Threat Detection version 5.0, RSA Web Threat Detection version 5.1, RSA Web Threat Detection version 5.1.2 h...
CVE-2016-0371MEDIUM5.5The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application ...
CVE-2016-3022MEDIUM6.5IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due...
CVE-2016-9039MEDIUM6.2An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability i...
CVE-2016-2050MEDIUM6.5The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers to cause a denial of service (out-of-bou...
CVE-2016-2402MEDIUM5.9OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a c...
CVE-2016-2518MEDIUM5.3The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-o...
CVE-2016-9401MEDIUM5.5popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
CVE-2016-7410MEDIUM5.5The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (...
CVE-2016-4055MEDIUM6.5The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of servi...
CVE-2016-7906MEDIUM5.5magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a cr...
CVE-2016-7799MEDIUM6.5MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds r...
CVE-2016-7101MEDIUM6.5The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) v...
CVE-2016-9811MEDIUM4.7The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc,...
CVE-2016-10027MEDIUM5.9Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allow...
CVE-2016-8334MEDIUM6.8A large out-of-bounds read on the heap vulnerability in Foxit PDF Reader can potentially be abused for information discl...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now