2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9955 | — | — | 1.2% | Feb 17, 2017 | The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof sig... |
| CVE-2016-9831 | — | — | 2.1% | Feb 17, 2017 | Heap-based buffer overflow in the parseSWF_RGBA function in parser.c in the listswf tool in libming 0.4.7 allows remote ... |
| CVE-2016-9829 | — | — | 2.1% | Feb 17, 2017 | Heap-based buffer overflow in the parseSWF_DEFINEFONT function in parser.c in the listswf tool in libming 0.4.7 allows r... |
| CVE-2016-9828 | — | — | 1.9% | Feb 17, 2017 | The dumpBuffer function in read.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of serv... |
| CVE-2016-9827 | — | — | 1.8% | Feb 17, 2017 | The _iprintf function in outputtxt.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of s... |
| CVE-2016-9814 | — | — | 2.4% | Feb 17, 2017 | The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library be... |
| CVE-2016-9773 | — | — | 1.8% | Feb 17, 2017 | Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remo... |
| CVE-2016-9637 | — | — | 0.4% | Feb 17, 2017 | The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow l... |
| CVE-2016-9139 | — | — | 0.8% | Feb 17, 2017 | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, ... |
| CVE-2016-8652 | — | — | 48.2% | Feb 17, 2017 | The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial... |
| CVE-2016-6233 | — | — | 2.0% | Feb 17, 2017 | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers ... |
| CVE-2016-5417 | — | — | 3.4% | Feb 17, 2017 | Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc... |
| CVE-2016-4861 | — | — | 4.1% | Feb 17, 2017 | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers ... |
| CVE-2016-4327 | — | — | 1.8% | Feb 17, 2017 | Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earl... |
| CVE-2016-4316 | — | — | 4.0% | Feb 17, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web ... |
| CVE-2016-4315 | — | — | 2.8% | Feb 17, 2017 | Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio... |
| CVE-2016-4314 | — | — | 12.4% | Feb 17, 2017 | Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini... |
| CVE-2016-4312 | — | — | 6.0% | Feb 17, 2017 | XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH... |
| CVE-2016-4311 | — | — | 3.4% | Feb 17, 2017 | Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote at... |
| CVE-2016-1249 | — | — | 2.4% | Feb 17, 2017 | The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to caus... |
| CVE-2016-10134 | — | — | 83.3% | Feb 17, 2017 | SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQ... |
| CVE-2016-6062 | — | — | 0.7% | Feb 16, 2017 | IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar... |
| CVE-2016-5919 | — | — | 0.7% | Feb 16, 2017 | IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that coul... |
| CVE-2016-7293 | — | — | — | Feb 16, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-8681 | MEDIUM | 5.5 | 2.1% | Feb 15, 2017 | The _dwarf_get_abbrev_for_code function in dwarf_util.c in libdwarf 20161001 and earlier allows remote attackers to caus... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now