2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-2370——A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sen...
CVE-2016-2369——A NULL pointer dereference vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT d...
CVE-2016-2368——Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT ...
CVE-2016-2367——An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the serv...
CVE-2016-2366——A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sen...
CVE-2016-2365——A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sen...
CVE-2016-2339——An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Rub...
CVE-2016-2337——Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String...
CVE-2016-2336——Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing diff...
CVE-2016-1550——An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb...
CVE-2016-1549——A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection al...
CVE-2016-1548——An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timesta...
CVE-2016-1547——An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec ...
CVE-2016-1515——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8789. Reason: This candidate is a reservation ...
CVE-2016-1514——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8790. Reason: This candidate is a reservation ...
CVE-2016-8006——Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAf...
CVE-2016-6892——The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of ...
CVE-2016-6891——MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit...
CVE-2016-6890——Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Sub...
CVE-2016-10030——The _prolog_error function in slurmd/req.c in Slurm before 15.08.13, 16.x before 16.05.7, and 17.x before 17.02.0-pre4 h...
CVE-2016-7169——Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php ...
CVE-2016-7168——Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress...
CVE-2016-7903——Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to m...
CVE-2016-7902——Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authentica...
CVE-2016-7399——scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3,...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now