2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9039 | MEDIUM | 6.2 | 0.5% | Jan 31, 2017 | An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability i... |
| CVE-2016-6621 | — | — | 1.9% | Jan 31, 2017 | The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers... |
| CVE-2016-5117 | — | — | 0.7% | Jan 31, 2017 | OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass th... |
| CVE-2016-3176 | — | — | 0.9% | Jan 31, 2017 | Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to byp... |
| CVE-2016-2050 | MEDIUM | 6.5 | 1.5% | Jan 31, 2017 | The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers to cause a denial of service (out-of-bou... |
| CVE-2016-10043 | — | — | 9.5% | Jan 31, 2017 | An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis... |
| CVE-2016-9249 | — | — | 2.0% | Jan 31, 2017 | An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Mana... |
| CVE-2016-9132 | — | — | 2.0% | Jan 30, 2017 | In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect l... |
| CVE-2016-9119 | — | — | 1.5% | Jan 30, 2017 | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attac... |
| CVE-2016-7798 | HIGH | 7.5 | 3.2% | Jan 30, 2017 | The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the ... |
| CVE-2016-6604 | — | — | 2.6% | Jan 30, 2017 | NULL pointer dereference in Samsung Exynos fimg2d driver for Android L(5.0/5.1) and M(6.0) allows attackers to have unsp... |
| CVE-2016-6270 | HIGH | 8.8 | 6.1% | Jan 30, 2017 | The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile ... |
| CVE-2016-6269 | CRITICAL | 9.1 | 3.7% | Jan 30, 2017 | Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before bu... |
| CVE-2016-6268 | HIGH | 7.8 | 1.0% | Jan 30, 2017 | Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local... |
| CVE-2016-6267 | HIGH | 8.8 | 54.9% | Jan 30, 2017 | SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330... |
| CVE-2016-6266 | HIGH | 8.8 | 8.2% | Jan 30, 2017 | ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before... |
| CVE-2016-6167 | HIGH | 7.8 | 0.8% | Jan 30, 2017 | Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduc... |
| CVE-2016-5434 | — | — | 1.5% | Jan 30, 2017 | libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds r... |
| CVE-2016-5026 | — | — | 0.3% | Jan 30, 2017 | hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare dire... |
| CVE-2016-2402 | MEDIUM | 5.9 | 2.2% | Jan 30, 2017 | OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a c... |
| CVE-2016-2399 | — | — | 7.2% | Jan 30, 2017 | Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to caus... |
| CVE-2016-2217 | — | — | 2.5% | Jan 30, 2017 | The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it ... |
| CVE-2016-10087 | — | — | 5.5% | Jan 30, 2017 | The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28,... |
| CVE-2016-9939 | — | — | 4.2% | Jan 30, 2017 | Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will alloca... |
| CVE-2016-7544 | — | — | 2.7% | Jan 30, 2017 | Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now