2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-2242——Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/...
CVE-2016-1925——Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value fo...
CVE-2016-1417——Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct...
CVE-2016-1281——Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibl...
CVE-2016-0769——Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote adm...
CVE-2016-0765——Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow r...
CVE-2016-9870——EMC Isilon OneFS 8.0.0.0, EMC Isilon OneFS 7.2.1.0 - 7.2.1.2, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1...
CVE-2016-8213——EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6....
CVE-2016-10157——Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete p...
CVE-2016-10156——A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd tim...
CVE-2016-10104——Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the Read attribute being set...
CVE-2016-10103——Information Disclosure can occur in encryptionProfiles.jsd in Hitek Software's Automize because of the Read attribute be...
CVE-2016-10102——hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and Encryption profile passwords. T...
CVE-2016-10101——Information Disclosure can occur in Hitek Software's Automize 10.x and 11.x passManager.jsd. Users have the Read attribu...
CVE-2016-9436——parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash ...
CVE-2016-9435——The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows re...
CVE-2016-6253——mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or...
CVE-2016-5323——The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-z...
CVE-2016-5321——The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and...
CVE-2016-5319——Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the applicati...
CVE-2016-5318——Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash...
CVE-2016-5317——Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier...
CVE-2016-5316——Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attacker...
CVE-2016-8644——In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
CVE-2016-8643——In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now