2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6129HIGH7.5The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate t...
CVE-2016-5100——Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attacker...
CVE-2016-4547——Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) ...
CVE-2016-4546——Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service c...
CVE-2016-3995——The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka...
CVE-2016-3616——The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and applicat...
CVE-2016-2788——MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary cod...
CVE-2016-2787——The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates...
CVE-2016-2568HIGH7.8pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl ca...
CVE-2016-10026——ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git...
CVE-2016-6210MEDIUM5.9sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static ...
CVE-2016-8495——An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 al...
CVE-2016-8713HIGH7.8A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5....
CVE-2016-8711HIGH7.8A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially cra...
CVE-2016-8709HIGH7.8A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A...
CVE-2016-10216——An issue was discovered in IT ITems DataBase (ITDB) through 1.23. The vulnerability exists due to insufficient filtratio...
CVE-2016-10215——An issue was discovered in Fastspot BigTree bigtree-form-builder before 1.2. The vulnerability exists due to insufficien...
CVE-2016-9244——A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may...
CVE-2016-8494——Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary c...
CVE-2016-6173——NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server ...
CVE-2016-6171HIGH8.6Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) ...
CVE-2016-5727——LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and exec...
CVE-2016-5726——Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and exec...
CVE-2016-4988MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote att...
CVE-2016-4987MEDIUM6.5Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbi...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now