2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-3298MEDIUM6.5Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 an...
CVE-2016-7423MEDIUM4.4The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation...
CVE-2016-1000007MEDIUM6.1Pagure 2.2.1 XSS in raw file endpoint
CVE-2016-1000114MEDIUM6.1XSS in huge IT gallery v1.1.5 for Joomla
CVE-2016-1454MEDIUM6.5Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 90...
CVE-2016-6418MEDIUM6.1Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4...
CVE-2016-7909MEDIUM4.4The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to caus...
CVE-2016-7908MEDIUM4.4The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descripto...
CVE-2016-7907MEDIUM4.4The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descripto...
CVE-2016-6306MEDIUM5.9The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial o...
CVE-2016-5172MEDIUM6.5The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers...
CVE-2016-4278MEDIUM6.5Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635...
CVE-2016-4277MEDIUM6.5Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635...
CVE-2016-4271MEDIUM6.5Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635...
CVE-2016-3351MEDIUM6.5Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a...
CVE-2016-6351MEDIUM6.7The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation...
CVE-2016-5430MEDIUM5.3The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling ...
CVE-2016-5107MEDIUM6The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allo...
CVE-2016-5106MEDIUM6The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Ada...
CVE-2016-5105MEDIUM4.4The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter e...
CVE-2016-4952MEDIUM6QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS a...
CVE-2016-6298MEDIUM5.3The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling pro...
CVE-2016-4655MEDIUM5.5The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
CVE-2016-5845MEDIUM5.5SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to ca...
CVE-2016-6207MEDIUM6.5Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now