2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-8686 | — | — | 1.5% | Jan 31, 2017 | The bm_new function in bitmap.h in potrace 1.13 allows remote attackers to have unspecified impact via a crafted image, ... |
| CVE-2016-8685 | — | — | 1.4% | Jan 31, 2017 | The findnext function in decompose.c in potrace 1.13 allows remote attackers to cause a denial of service (invalid memor... |
| CVE-2016-6329 | — | — | 5.9% | Jan 31, 2017 | OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday ... |
| CVE-2016-6285 | — | — | 2.1% | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 a... |
| CVE-2016-6621 | — | — | 1.9% | Jan 31, 2017 | The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers... |
| CVE-2016-5117 | — | — | 0.7% | Jan 31, 2017 | OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass th... |
| CVE-2016-3176 | — | — | 0.9% | Jan 31, 2017 | Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to byp... |
| CVE-2016-10043 | — | — | 9.5% | Jan 31, 2017 | An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis... |
| CVE-2016-9249 | — | — | 2.0% | Jan 31, 2017 | An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Mana... |
| CVE-2016-9132 | — | — | 2.0% | Jan 30, 2017 | In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect l... |
| CVE-2016-9119 | — | — | 1.5% | Jan 30, 2017 | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attac... |
| CVE-2016-6604 | — | — | 2.6% | Jan 30, 2017 | NULL pointer dereference in Samsung Exynos fimg2d driver for Android L(5.0/5.1) and M(6.0) allows attackers to have unsp... |
| CVE-2016-5434 | — | — | 1.5% | Jan 30, 2017 | libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds r... |
| CVE-2016-5026 | — | — | 0.3% | Jan 30, 2017 | hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare dire... |
| CVE-2016-2399 | — | — | 7.2% | Jan 30, 2017 | Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to caus... |
| CVE-2016-2217 | — | — | 2.5% | Jan 30, 2017 | The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it ... |
| CVE-2016-10087 | — | — | 5.5% | Jan 30, 2017 | The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28,... |
| CVE-2016-9939 | — | — | 4.2% | Jan 30, 2017 | Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will alloca... |
| CVE-2016-7544 | — | — | 2.7% | Jan 30, 2017 | Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block ... |
| CVE-2016-2519 | — | — | 6.9% | Jan 30, 2017 | ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (ntpd abort) by ... |
| CVE-2016-2517 | — | — | 8.8% | Jan 30, 2017 | NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent auth... |
| CVE-2016-2516 | — | — | 9.0% | Jan 30, 2017 | NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service ... |
| CVE-2016-10176 | — | — | 77.4% | Jan 30, 2017 | The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the w... |
| CVE-2016-10175 | — | — | 64.7% | Jan 30, 2017 | The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. Thi... |
| CVE-2016-9554 | — | — | 24.4% | Jan 28, 2017 | The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injectio... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now