2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-7904——Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the au...
CVE-2016-8207——A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to...
CVE-2016-8206——A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prio...
CVE-2016-8205——A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prio...
CVE-2016-8204CRITICAL9.8A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and ...
CVE-2016-8201——A CSRF vulnerability in Brocade Virtual Traffic Manager versions released prior to and including 11.0 could allow an att...
CVE-2016-10142——An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of...
CVE-2016-9813——The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of ser...
CVE-2016-9812——The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a ...
CVE-2016-9811MEDIUM4.7The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc,...
CVE-2016-9810——The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows ...
CVE-2016-9809——Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unsp...
CVE-2016-9808——The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write an...
CVE-2016-9807——The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a deni...
CVE-2016-9312——ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UD...
CVE-2016-9311——ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL...
CVE-2016-9310——The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via ...
CVE-2016-9107——The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensit...
CVE-2016-8883——The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of servi...
CVE-2016-8882——The jpc_dec_tilefini function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a den...
CVE-2016-8881——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4517. Reason: This candidate is a duplicate of C...
CVE-2016-8880——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4516. Reason: This candidate is a duplicate of C...
CVE-2016-8671——The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might a...
CVE-2016-8467——An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem comma...
CVE-2016-7434HIGH7.5The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a craf...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now