2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-7408——The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2...
CVE-2016-7407——The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted Open...
CVE-2016-7406——Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format ...
CVE-2016-6884——TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of...
CVE-2016-6883——MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a B...
CVE-2016-6882——MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain...
CVE-2016-10206——Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the aut...
CVE-2016-10205——Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMS...
CVE-2016-10204——SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via...
CVE-2016-10203——Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web ...
CVE-2016-10202——Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web ...
CVE-2016-10201——Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web ...
CVE-2016-10194——The festivaltts4r gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a strin...
CVE-2016-10193——The espeak-ruby gem before 1.0.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters...
CVE-2016-10127——PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
CVE-2016-9892——The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6....
CVE-2016-10071MEDIUM5.5coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and ...
CVE-2016-10069——coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via ...
CVE-2016-10068——The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fau...
CVE-2016-10067——magick/memory.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) v...
CVE-2016-10064HIGH7.8Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (app...
CVE-2016-10063HIGH7.8Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (app...
CVE-2016-10062MEDIUM5.5The ReadGROUP4Image function in coders/tiff.c in ImageMagick does not check the return value of the fwrite function, whi...
CVE-2016-10060MEDIUM6.5The ConcatenateImages function in MagickWand/magick-cli.c in ImageMagick before 7.0.1-10 does not check the return value...
CVE-2016-10228——The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now