2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-8688——The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remot...
CVE-2016-8687——Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to ca...
CVE-2016-8684——The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact...
CVE-2016-8683——The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact vi...
CVE-2016-8682——The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service ...
CVE-2016-6866——slock allows attackers to bypass the screen lock via vectors involving an invalid password hash, which triggers a NULL p...
CVE-2016-6832——Heap-based buffer overflow in the ff_audio_resample function in resample.c in libav before 11.4 allows remote attackers ...
CVE-2016-6079——IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to ob...
CVE-2016-6077——IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user th...
CVE-2016-6060——An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see...
CVE-2016-6033——IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could...
CVE-2016-3694——Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-modul...
CVE-2016-0360——IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sourc...
CVE-2016-1889——Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of gu...
CVE-2016-1888——The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and ...
CVE-2016-1883——The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain pri...
CVE-2016-1881——The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain pr...
CVE-2016-1880——The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel...
CVE-2016-10089——Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script fil...
CVE-2016-10223——An issue was discovered in BigTree CMS before 4.2.15. The vulnerability exists due to insufficient filtration of user-su...
CVE-2016-9355——An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior...
CVE-2016-8375——An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior...
CVE-2016-8358——An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. The aff...
CVE-2016-8355——An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. CADD-So...
CVE-2016-9371——An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now