2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9279 | — | — | 2.0% | Jan 18, 2017 | Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets al... |
| CVE-2016-9278 | — | — | 0.4% | Jan 18, 2017 | The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a deni... |
| CVE-2016-9273 | — | — | 3.8% | Jan 18, 2017 | tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file,... |
| CVE-2016-9109 | — | — | 2.2% | Jan 18, 2017 | Artifex Software MuJS allows attackers to cause a denial of service (crash) via vectors related to incomplete escape seq... |
| CVE-2016-7999 | — | — | 2.3% | Jan 18, 2017 | ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SS... |
| CVE-2016-7998 | — | — | 13.6% | Jan 18, 2017 | The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP... |
| CVE-2016-7997 | — | — | 3.4% | Jan 18, 2017 | The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (asserti... |
| CVE-2016-7996 | — | — | 3.9% | Jan 18, 2017 | Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have... |
| CVE-2016-7982 | — | — | 20.5% | Jan 18, 2017 | Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to en... |
| CVE-2016-7981 | — | — | 8.2% | Jan 18, 2017 | Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject ... |
| CVE-2016-7980 | — | — | 4.1% | Jan 18, 2017 | Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote a... |
| CVE-2016-7906 | MEDIUM | 5.5 | 1.7% | Jan 18, 2017 | magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a cr... |
| CVE-2016-7799 | MEDIUM | 6.5 | 3.6% | Jan 18, 2017 | MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds r... |
| CVE-2016-7564 | — | — | 1.7% | Jan 18, 2017 | Heap-based buffer overflow in the Fp_toString function in jsfunction.c in Artifex Software MuJS allows attackers to caus... |
| CVE-2016-7563 | — | — | 1.5% | Jan 18, 2017 | The chartorune function in Artifex Software MuJS allows attackers to cause a denial of service (out-of-bounds read) via ... |
| CVE-2016-7150 | — | — | 0.9% | Jan 18, 2017 | Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject ar... |
| CVE-2016-7149 | — | — | 1.2% | Jan 18, 2017 | Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote attackers to inject arbitrary we... |
| CVE-2016-7144 | — | — | 1.3% | Jan 18, 2017 | The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attacke... |
| CVE-2016-7101 | MEDIUM | 6.5 | 2.7% | Jan 18, 2017 | The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) v... |
| CVE-2016-6823 | HIGH | 7.5 | 4.8% | Jan 18, 2017 | Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (c... |
| CVE-2016-6527 | — | — | 1.5% | Jan 18, 2017 | The SmartCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to... |
| CVE-2016-6526 | — | — | 1.5% | Jan 18, 2017 | The SpamCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to ... |
| CVE-2016-2233 | — | — | 34.7% | Jan 18, 2017 | Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC serve... |
| CVE-2016-2087 | — | — | 9.4% | Jan 18, 2017 | Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary ... |
| CVE-2016-7904 | — | — | 1.0% | Jan 16, 2017 | Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the au... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now