2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9436 | — | — | 3.3% | Jan 20, 2017 | parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash ... |
| CVE-2016-9435 | — | — | 3.3% | Jan 20, 2017 | The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows re... |
| CVE-2016-6253 | — | — | 3.5% | Jan 20, 2017 | mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or... |
| CVE-2016-5323 | — | — | 5.7% | Jan 20, 2017 | The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-z... |
| CVE-2016-5321 | — | — | 2.9% | Jan 20, 2017 | The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and... |
| CVE-2016-5319 | — | — | 3.7% | Jan 20, 2017 | Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the applicati... |
| CVE-2016-5318 | — | — | 4.8% | Jan 20, 2017 | Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash... |
| CVE-2016-5317 | — | — | 2.0% | Jan 20, 2017 | Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier... |
| CVE-2016-5316 | — | — | 2.2% | Jan 20, 2017 | Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attacker... |
| CVE-2016-8644 | — | — | 1.2% | Jan 20, 2017 | In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context. |
| CVE-2016-8643 | — | — | 0.7% | Jan 20, 2017 | In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. |
| CVE-2016-8642 | — | — | 1.2% | Jan 20, 2017 | In Moodle 2.x and 3.x, the question engine allows access to files that should not be available. |
| CVE-2016-7038 | — | — | 1.0% | Jan 20, 2017 | In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. |
| CVE-2016-5014 | — | — | 1.0% | Jan 20, 2017 | In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer acce... |
| CVE-2016-5013 | — | — | 0.9% | Jan 20, 2017 | In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam. |
| CVE-2016-5012 | — | — | 1.2% | Jan 20, 2017 | In Moodle 3.x, glossary search displays entries without checking user permissions to view them. |
| CVE-2016-10143 | — | — | 1.8% | Jan 20, 2017 | A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a c... |
| CVE-2016-5725 | — | — | 24.1% | Jan 19, 2017 | Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allow... |
| CVE-2016-9016 | — | — | 0.4% | Jan 19, 2017 | Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl ca... |
| CVE-2016-7794 | — | — | 3.5% | Jan 19, 2017 | sociomantic-tsunami git-hub before 0.10.3 allows remote attackers to execute arbitrary code via a crafted repository nam... |
| CVE-2016-7793 | — | — | 3.3% | Jan 19, 2017 | sociomantic-tsunami git-hub before 0.10.3 allows remote attackers to execute arbitrary code via a crafted repository URL... |
| CVE-2016-7545 | — | — | 0.4% | Jan 19, 2017 | SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI io... |
| CVE-2016-7543 | — | — | 0.6% | Jan 19, 2017 | Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 envi... |
| CVE-2016-10075 | — | — | 0.4% | Jan 19, 2017 | The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo... |
| CVE-2016-9650 | — | — | 1.1% | Jan 19, 2017 | Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handle... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now