2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-9380The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest O...
CVE-2016-9379The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS...
CVE-2016-9081Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perfor...
CVE-2016-9012CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuratio...
CVE-2016-7792Ubiquiti Networks UniFi 5.2.7 does not restrict access to the database, which allows remote attackers to modify the data...
CVE-2016-7102ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan lib...
CVE-2016-7037The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for...
CVE-2016-7036python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time compar...
CVE-2016-6920Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attacke...
CVE-2016-6603ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users v...
CVE-2016-6602ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependen...
CVE-2016-6601Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem...
CVE-2016-6600Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remot...
CVE-2016-6582The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary toke...
CVE-2016-6521Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0....
CVE-2016-6517Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (enco...
CVE-2016-6484CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitr...
CVE-2016-6223The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to ca...
CVE-2016-6164Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1...
CVE-2016-6160tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a lar...
CVE-2016-5876ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download ...
CVE-2016-5873Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbi...
CVE-2016-5742SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before ...
CVE-2016-5720Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduc...
CVE-2016-5697Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now