2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2519 | — | — | 6.9% | Jan 30, 2017 | ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (ntpd abort) by ... |
| CVE-2016-2518 | MEDIUM | 5.3 | 15.2% | Jan 30, 2017 | The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-o... |
| CVE-2016-2517 | — | — | 8.8% | Jan 30, 2017 | NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent auth... |
| CVE-2016-2516 | — | — | 9.0% | Jan 30, 2017 | NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service ... |
| CVE-2016-10186 | HIGH | 7.5 | 4.2% | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules. |
| CVE-2016-10185 | HIGH | 7.5 | 4.2% | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf. |
| CVE-2016-10184 | HIGH | 7.5 | 5.6% | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal. |
| CVE-2016-10183 | HIGH | 7.5 | 5.6% | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal. |
| CVE-2016-10182 | CRITICAL | 9.8 | 9.2% | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters. |
| CVE-2016-10181 | HIGH | 7.5 | 3.9% | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg req... |
| CVE-2016-10180 | HIGH | 7.5 | 4.4% | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding. |
| CVE-2016-10179 | HIGH | 7.5 | 4.9% | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607. |
| CVE-2016-10178 | CRITICAL | 9.8 | 7.3% | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/s... |
| CVE-2016-10177 | CRITICAL | 9.8 | 6.9% | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with... |
| CVE-2016-10176 | — | — | 77.4% | Jan 30, 2017 | The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the w... |
| CVE-2016-10175 | — | — | 64.7% | Jan 30, 2017 | The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. Thi... |
| CVE-2016-10174 | CRITICAL | 9.8 | 83.5% | Jan 30, 2017 | The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg... |
| CVE-2016-9554 | — | — | 24.4% | Jan 28, 2017 | The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injectio... |
| CVE-2016-9553 | — | — | 19.3% | Jan 28, 2017 | The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its w... |
| CVE-2016-8575 | — | — | 5.4% | Jan 28, 2017 | The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability tha... |
| CVE-2016-8574 | — | — | 3.1% | Jan 28, 2017 | The FRF.15 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:frf15_print(). |
| CVE-2016-7993 | — | — | 3.3% | Jan 28, 2017 | A bug in util-print.c:relts_print() in tcpdump before 4.9.0 could cause a buffer overflow in multiple protocol parsers (... |
| CVE-2016-7992 | — | — | 3.3% | Jan 28, 2017 | The Classical IP over ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-cip.c:cip_if_print(). |
| CVE-2016-7986 | — | — | 3.1% | Jan 28, 2017 | The GeoNetworking parser in tcpdump before 4.9.0 has a buffer overflow in print-geonet.c, multiple functions. |
| CVE-2016-7985 | — | — | 3.1% | Jan 28, 2017 | The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print(). |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now