2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7407 | — | — | 5.5% | Mar 3, 2017 | The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted Open... |
| CVE-2016-7406 | — | — | 10.5% | Mar 3, 2017 | Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format ... |
| CVE-2016-6884 | — | — | 1.3% | Mar 3, 2017 | TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of... |
| CVE-2016-6883 | — | — | 13.9% | Mar 3, 2017 | MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a B... |
| CVE-2016-6882 | — | — | 1.3% | Mar 3, 2017 | MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain... |
| CVE-2016-10206 | — | — | 0.7% | Mar 3, 2017 | Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the aut... |
| CVE-2016-10205 | — | — | 1.4% | Mar 3, 2017 | Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMS... |
| CVE-2016-10204 | — | — | 2.1% | Mar 3, 2017 | SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via... |
| CVE-2016-10203 | — | — | 1.1% | Mar 3, 2017 | Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web ... |
| CVE-2016-10202 | — | — | 0.8% | Mar 3, 2017 | Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web ... |
| CVE-2016-10201 | — | — | 0.8% | Mar 3, 2017 | Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web ... |
| CVE-2016-10194 | — | — | 2.6% | Mar 3, 2017 | The festivaltts4r gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a strin... |
| CVE-2016-10193 | — | — | 2.5% | Mar 3, 2017 | The espeak-ruby gem before 1.0.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters... |
| CVE-2016-10127 | — | — | 2.1% | Mar 3, 2017 | PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response. |
| CVE-2016-9892 | — | — | 1.7% | Mar 2, 2017 | The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.... |
| CVE-2016-10071 | MEDIUM | 5.5 | 1.9% | Mar 2, 2017 | coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and ... |
| CVE-2016-10069 | — | — | 1.9% | Mar 2, 2017 | coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via ... |
| CVE-2016-10068 | — | — | 1.9% | Mar 2, 2017 | The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fau... |
| CVE-2016-10067 | — | — | 3.0% | Mar 2, 2017 | magick/memory.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) v... |
| CVE-2016-10064 | HIGH | 7.8 | 2.1% | Mar 2, 2017 | Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (app... |
| CVE-2016-10063 | HIGH | 7.8 | 2.3% | Mar 2, 2017 | Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (app... |
| CVE-2016-10062 | MEDIUM | 5.5 | 1.8% | Mar 2, 2017 | The ReadGROUP4Image function in coders/tiff.c in ImageMagick does not check the return value of the fwrite function, whi... |
| CVE-2016-10060 | MEDIUM | 6.5 | 2.3% | Mar 2, 2017 | The ConcatenateImages function in MagickWand/magick-cli.c in ImageMagick before 7.0.1-10 does not check the return value... |
| CVE-2016-10228 | — | — | 4.0% | Mar 2, 2017 | The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the... |
| CVE-2016-8233 | — | — | 1.1% | Mar 1, 2017 | Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now