2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-4911MEDIUM4.3The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users...
CVE-2016-4429MEDIUM5.9Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) ...
CVE-2016-1222MEDIUM6.1Cross-site scripting (XSS) vulnerability in Kobe Beauty php-contact-form before 2016-05-18 allows remote attackers to in...
CVE-2016-4454MEDIUM6The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sens...
CVE-2016-4453MEDIUM4.4The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial o...
CVE-2016-3094MEDIUM5.9PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allow...
CVE-2016-4020MEDIUM6.5The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local ...
CVE-2016-0264MEDIUM5.6Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 ...
CVE-2016-4037MEDIUM6The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of s...
CVE-2016-4441MEDIUM6The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DM...
CVE-2016-4439MEDIUM6.7The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly ch...
CVE-2016-4425MEDIUM6.5Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumpti...
CVE-2016-3721MEDIUM4.3Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters in...
CVE-2016-3712MEDIUM5.5Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read ...
CVE-2016-1115MEDIUM5.9Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields o...
CVE-2016-1113MEDIUM6.1Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Up...
CVE-2016-3718MEDIUM5.5The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct ...
CVE-2016-3715MEDIUM5.5The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary fi...
CVE-2016-2107MEDIUM5.9The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a ...
CVE-2016-2782MEDIUM4.6The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attack...
CVE-2016-2383MEDIUM5.5The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the ...
CVE-2016-0668MEDIUM4.1Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 an...
CVE-2016-0651MEDIUM5.5Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availability via vectors relat...
CVE-2016-0642MEDIUM4.7Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local us...
CVE-2016-0162MEDIUM4.3Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScr...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now