2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1925 | — | — | 3.0% | Jan 23, 2017 | Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value fo... |
| CVE-2016-1417 | — | — | 4.4% | Jan 23, 2017 | Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct... |
| CVE-2016-1281 | — | — | 0.8% | Jan 23, 2017 | Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibl... |
| CVE-2016-0769 | — | — | 2.9% | Jan 23, 2017 | Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote adm... |
| CVE-2016-0765 | — | — | 1.8% | Jan 23, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow r... |
| CVE-2016-9870 | — | — | 0.4% | Jan 23, 2017 | EMC Isilon OneFS 8.0.0.0, EMC Isilon OneFS 7.2.1.0 - 7.2.1.2, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1... |
| CVE-2016-8213 | — | — | 1.0% | Jan 23, 2017 | EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6.... |
| CVE-2016-10157 | — | — | 2.2% | Jan 23, 2017 | Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete p... |
| CVE-2016-10156 | — | — | 1.2% | Jan 23, 2017 | A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd tim... |
| CVE-2016-10104 | — | — | 0.6% | Jan 23, 2017 | Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the Read attribute being set... |
| CVE-2016-10103 | — | — | 0.4% | Jan 23, 2017 | Information Disclosure can occur in encryptionProfiles.jsd in Hitek Software's Automize because of the Read attribute be... |
| CVE-2016-10102 | — | — | 0.4% | Jan 23, 2017 | hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and Encryption profile passwords. T... |
| CVE-2016-10101 | — | — | 0.6% | Jan 23, 2017 | Information Disclosure can occur in Hitek Software's Automize 10.x and 11.x passManager.jsd. Users have the Read attribu... |
| CVE-2016-9436 | — | — | 3.3% | Jan 20, 2017 | parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash ... |
| CVE-2016-9435 | — | — | 3.3% | Jan 20, 2017 | The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows re... |
| CVE-2016-6253 | — | — | 3.5% | Jan 20, 2017 | mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or... |
| CVE-2016-5323 | — | — | 5.7% | Jan 20, 2017 | The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-z... |
| CVE-2016-5321 | — | — | 2.9% | Jan 20, 2017 | The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and... |
| CVE-2016-5319 | — | — | 3.7% | Jan 20, 2017 | Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the applicati... |
| CVE-2016-5318 | — | — | 4.8% | Jan 20, 2017 | Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash... |
| CVE-2016-5317 | — | — | 2.0% | Jan 20, 2017 | Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier... |
| CVE-2016-5316 | — | — | 2.2% | Jan 20, 2017 | Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attacker... |
| CVE-2016-8644 | — | — | 1.2% | Jan 20, 2017 | In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context. |
| CVE-2016-8643 | — | — | 0.7% | Jan 20, 2017 | In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. |
| CVE-2016-8642 | — | — | 1.2% | Jan 20, 2017 | In Moodle 2.x and 3.x, the question engine allows access to files that should not be available. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now