2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-9446HIGH7.5The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensiti...
CVE-2016-9445HIGH7.5Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via l...
CVE-2016-9401MEDIUM5.5popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
CVE-2016-9386The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow l...
CVE-2016-9385The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrator...
CVE-2016-9383Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently ob...
CVE-2016-9382Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to ga...
CVE-2016-9381HIGH7.5Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data o...
CVE-2016-9380The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest O...
CVE-2016-9379The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS...
CVE-2016-9081Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perfor...
CVE-2016-9012CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuratio...
CVE-2016-7792Ubiquiti Networks UniFi 5.2.7 does not restrict access to the database, which allows remote attackers to modify the data...
CVE-2016-7567CRITICAL9.8Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have...
CVE-2016-7410MEDIUM5.5The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (...
CVE-2016-7102ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan lib...
CVE-2016-7037The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for...
CVE-2016-7036python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time compar...
CVE-2016-6920Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attacke...
CVE-2016-6668HIGH7.5The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 befor...
CVE-2016-6603ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users v...
CVE-2016-6602ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependen...
CVE-2016-6601Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem...
CVE-2016-6600Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remot...
CVE-2016-6582The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary toke...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now