2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2016-8632HIGH7.8The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship betw...
CVE-2016-9562HIGH7.5SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage)...
CVE-2016-8562HIGH7.5A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < ...
CVE-2016-7913HIGH7.8The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users ...
CVE-2016-7912HIGH7.8Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux ker...
CVE-2016-7911HIGH7.8Race condition in the get_task_ioprio function in block/ioprio.c in the Linux kernel before 4.6.6 allows local users to ...
CVE-2016-7910HIGH7.8Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in the Linux kernel before 4.7.1 allows loc...
CVE-2016-9294HIGH7.5Artifex Software, Inc. MuJS before 5008105780c0b0182ea6eda83ad5598f225be3ee allows context-dependent attackers to conduc...
CVE-2016-9274HIGH7.8Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git....
CVE-2016-5195HIGH7Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev...
CVE-2016-7256HIGH8.8atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,...
CVE-2016-7255HIGH7.8The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, ...
CVE-2016-7201HIGH8.8The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de...
CVE-2016-7200HIGH8.8The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de...
CVE-2016-9136HIGH7.5Artifex Software, Inc. MuJS before a0ceaf5050faf419401fe1b83acfa950ec8a8a89 allows context-dependent attackers to obtain...
CVE-2016-8864HIGH7.5named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to c...
CVE-2016-7855HIGH8.8Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linu...
CVE-2016-7919HIGH7.5Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injectio...
CVE-2016-5625HIGH7Unspecified vulnerability in Oracle MySQL 5.7.14 and earlier allows local users to affect confidentiality, integrity, an...
CVE-2016-5558HIGH8.6Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.5.1 thro...
CVE-2016-8666HIGH7.5The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and ...
CVE-2016-7425HIGH7.8The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not rest...
CVE-2016-7039HIGH7.5The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption a...
CVE-2016-7193HIGH7.8Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for M...
CVE-2016-3393HIGH7.8Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now