2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2370 | — | — | 2.1% | Jan 6, 2017 | A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sen... |
| CVE-2016-2369 | — | — | 2.2% | Jan 6, 2017 | A NULL pointer dereference vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT d... |
| CVE-2016-2368 | — | — | 4.5% | Jan 6, 2017 | Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT ... |
| CVE-2016-2367 | — | — | 1.9% | Jan 6, 2017 | An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the serv... |
| CVE-2016-2366 | — | — | 2.5% | Jan 6, 2017 | A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sen... |
| CVE-2016-2365 | — | — | 2.4% | Jan 6, 2017 | A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sen... |
| CVE-2016-2339 | — | — | 5.1% | Jan 6, 2017 | An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Rub... |
| CVE-2016-2337 | — | — | 6.2% | Jan 6, 2017 | Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String... |
| CVE-2016-2336 | — | — | 3.3% | Jan 6, 2017 | Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing diff... |
| CVE-2016-1550 | — | — | 3.6% | Jan 6, 2017 | An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb... |
| CVE-2016-1549 | — | — | 3.1% | Jan 6, 2017 | A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection al... |
| CVE-2016-1548 | — | — | 3.8% | Jan 6, 2017 | An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timesta... |
| CVE-2016-1547 | — | — | 5.1% | Jan 6, 2017 | An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec ... |
| CVE-2016-1515 | — | — | — | Jan 6, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8789. Reason: This candidate is a reservation ... |
| CVE-2016-1514 | — | — | — | Jan 6, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8790. Reason: This candidate is a reservation ... |
| CVE-2016-8006 | — | — | 0.3% | Jan 5, 2017 | Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAf... |
| CVE-2016-6892 | — | — | 1.9% | Jan 5, 2017 | The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of ... |
| CVE-2016-6891 | — | — | 1.9% | Jan 5, 2017 | MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit... |
| CVE-2016-6890 | — | — | 6.4% | Jan 5, 2017 | Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Sub... |
| CVE-2016-10030 | — | — | 2.5% | Jan 5, 2017 | The _prolog_error function in slurmd/req.c in Slurm before 15.08.13, 16.x before 16.05.7, and 17.x before 17.02.0-pre4 h... |
| CVE-2016-7169 | — | — | 3.2% | Jan 5, 2017 | Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php ... |
| CVE-2016-7168 | — | — | 2.8% | Jan 5, 2017 | Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress... |
| CVE-2016-7903 | — | — | 1.1% | Jan 4, 2017 | Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to m... |
| CVE-2016-7902 | — | — | 3.0% | Jan 4, 2017 | Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authentica... |
| CVE-2016-7399 | — | — | 4.9% | Jan 4, 2017 | scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3,... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now