2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5100Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attacker...
CVE-2016-4547Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) ...
CVE-2016-4546Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service c...
CVE-2016-3995The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka...
CVE-2016-3616The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and applicat...
CVE-2016-2788MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary cod...
CVE-2016-2787The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates...
CVE-2016-2568HIGH7.8pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl ca...
CVE-2016-10026ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git...
CVE-2016-6210MEDIUM5.9sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static ...
CVE-2016-8495An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 al...
CVE-2016-8713HIGH7.8A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5....
CVE-2016-8711HIGH7.8A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially cra...
CVE-2016-8709HIGH7.8A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A...
CVE-2016-10216An issue was discovered in IT ITems DataBase (ITDB) through 1.23. The vulnerability exists due to insufficient filtratio...
CVE-2016-10215An issue was discovered in Fastspot BigTree bigtree-form-builder before 1.2. The vulnerability exists due to insufficien...
CVE-2016-9244A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may...
CVE-2016-8494Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary c...
CVE-2016-6173NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server ...
CVE-2016-6171HIGH8.6Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) ...
CVE-2016-5727LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and exec...
CVE-2016-5726Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and exec...
CVE-2016-4988MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote att...
CVE-2016-4987MEDIUM6.5Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbi...
CVE-2016-4986HIGH7.5Directory traversal vulnerability in the TAP plugin before 1.25 in Jenkins allows remote attackers to read arbitrary fil...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now