2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-9380——The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest O...
CVE-2016-9379——The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS...
CVE-2016-9081——Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perfor...
CVE-2016-9012——CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuratio...
CVE-2016-7792——Ubiquiti Networks UniFi 5.2.7 does not restrict access to the database, which allows remote attackers to modify the data...
CVE-2016-7102——ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan lib...
CVE-2016-7037——The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for...
CVE-2016-7036——python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time compar...
CVE-2016-6920——Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attacke...
CVE-2016-6603——ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users v...
CVE-2016-6602——ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependen...
CVE-2016-6601——Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem...
CVE-2016-6600——Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remot...
CVE-2016-6582——The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary toke...
CVE-2016-6521——Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0....
CVE-2016-6517——Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (enco...
CVE-2016-6484——CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitr...
CVE-2016-6223——The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to ca...
CVE-2016-6164——Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1...
CVE-2016-6160——tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a lar...
CVE-2016-5876——ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download ...
CVE-2016-5873——Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbi...
CVE-2016-5742——SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before ...
CVE-2016-5720——Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduc...
CVE-2016-5697——Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now